Malware

Malware.AI.2280642341 removal tips

Malware Removal

The Malware.AI.2280642341 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2280642341 virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2280642341?


File Info:

name: 64442AB7C793A645A41C.mlw
path: /opt/CAPEv2/storage/binaries/f66d3212de8c838865f1300286a60b5d1f6ba66b8806d7f9c2abbb49a8e68c61
crc32: C0F45466
md5: 64442ab7c793a645a41c8ea65dfd6783
sha1: 9d79f969b7d19b8b34b2634916e5e47f684a9f2b
sha256: f66d3212de8c838865f1300286a60b5d1f6ba66b8806d7f9c2abbb49a8e68c61
sha512: 0035284b453fbf37c6ac70d16db02138a45e214899f31cac9d7b173ee26204c92d8b6f6e7b03df930d5de850a9844fbc8d9f4164eef8a441fbf1c70130afbbc5
ssdeep: 192:cFo2bW+/Q+m1lpr60LsmB1LN65D1NGFaNJhLkwcud2DH9VwGfct3/SfWHk5:cFoeWmR2l80e5maNJawcudoD7UlSfCk5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7226C539A526A8EC07D51760DEBBF6E4444E16DAD8536EEBFE0343FCC817283D20585
sha3_384: dce3b13e13df8c23ab503d27ce0a39aacc67d5e8906f055efebe120657c5d428dbdbaeeb238ab268a195936877d59226
ep_bytes: 60be157040008dbeeb9fffff5789e58d
timestamp: 2017-06-28 16:39:28

Version Info:

0: [No Data]

Malware.AI.2280642341 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
AVGWin32:Malware-gen
tehtrisGeneric.Malware
DrWebTrojan.MulDrop7.36557
McAfeeArtemis!64442AB7C793
MalwarebytesMalware.AI.2280642341
SangforTrojan.Win32.Save.a
CynetMalicious (score: 100)
APEXMalicious
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:Malware-gen
McAfee-GW-EditionBehavesLike.Win32.BadFile.lh
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Tepfer.Plqt
Antiy-AVLTrojan/Win32.SGeneric
XcitiumTrojWare.Win32.TrojanDropper.Agent.DT@6n86dy
VBA32Trojan.MulDrop
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:BIr/sR0dGASEMXXwesF0yA)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Malware.AI.2280642341?

Malware.AI.2280642341 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment