Malware

Should I remove “Malware.AI.2281418886”?

Malware Removal

The Malware.AI.2281418886 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2281418886 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Malware.AI.2281418886?


File Info:

name: 1B49D4B245568BDA6752.mlw
path: /opt/CAPEv2/storage/binaries/5bca2f8454e1c78d701ebc86b282fa5a6742d5da555c61d09706b3c2a73153f9
crc32: C6F79499
md5: 1b49d4b245568bda6752dad65efeaedd
sha1: 1988a295cc01736bcb0b742b6ceec7fef2e5d4fc
sha256: 5bca2f8454e1c78d701ebc86b282fa5a6742d5da555c61d09706b3c2a73153f9
sha512: ed849278295682009edbe51f0a6ee2bb66b7e2c34f5431d6badee5753b4c0e35f09d91f8e8ef5ba8d4277734c2419ef3462ad6fb6d70b9f6f05907655fc8f242
ssdeep: 1536:qdujP/gtmqIJlwv20Q2Jhy5BJd7KoR/aF7/Sc47lIVxVWi60Z/BzxO:qduT/smq/dQyy5BbnR/O/2+3VWHkFxO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D17302950F1DEB43C917C0F12487A615B8DB22F1467AAB1E423CE102BBAB6094B5F657
sha3_384: cb6fc314c254d1acb4d0ba58fc9b2859d1f777f3188f5c359a459605d0824ec63db180d12a829e9501a22841be754049
ep_bytes: 60be005045008dbe00c0faff57eb0b90
timestamp: 2015-07-22 09:41:49

Version Info:

0: [No Data]

Malware.AI.2281418886 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader15.32871
MicroWorld-eScanDeepScan:Generic.PWStealer.7.748A8786
FireEyeGeneric.mg.1b49d4b245568bda
CAT-QuickHealTrojanPWS.QQPass.KB.mue
McAfeeGenericRXAA-FA!1B49D4B24556
CylanceUnsafe
ZillyaTrojan.Scar.Win32.93509
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.245568
BitDefenderThetaAI:Packer.FAB1226523
VirITTrojan.Win32.Generic.BU
CyrenW32/QQPass.AF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.QQPass.OUO
APEXMalicious
ClamAVWin.Trojan.Deepscan-72
KasperskyTrojan.Win32.Scar.kxey
BitDefenderDeepScan:Generic.PWStealer.7.748A8786
NANO-AntivirusTrojan.Win32.Scar.duoywy
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b3b30a
Ad-AwareDeepScan:Generic.PWStealer.7.748A8786
SophosML/PE-A + Mal/Emogen-P
BaiduWin32.Trojan-PSW.QQPass.ag
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
EmsisoftDeepScan:Generic.PWStealer.7.748A8786 (B)
IkarusTrojan.Win32.PSW
GDataWin32.Trojan.PSE.18PVCNI
JiangminTrojan.Generic.mcls
AviraHEUR/AGEN.1200608
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.186472F
ZoneAlarmTrojan.Win32.Scar.kxey
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Stealer.R143066
Acronissuspicious
VBA32Trojan.Scar
ALYacDeepScan:Generic.PWStealer.7.748A8786
MalwarebytesMalware.AI.2281418886
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/GameHack.AX!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.2281418886?

Malware.AI.2281418886 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment