Malware

Malware.AI.2309432668 removal tips

Malware Removal

The Malware.AI.2309432668 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2309432668 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:9999
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • A possible heap spray exploit has been detected
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing

How to determine Malware.AI.2309432668?


File Info:

name: 628F5AD4179412A8D539.mlw
path: /opt/CAPEv2/storage/binaries/7eb1e6878b4e4120c5cd5dfd252449847942dd5b07ddcda9c1313616763740ac
crc32: A3C1F6D0
md5: 628f5ad4179412a8d539dc370f37c5bb
sha1: cce7109114689317831d1369b8e54f74a7cf57eb
sha256: 7eb1e6878b4e4120c5cd5dfd252449847942dd5b07ddcda9c1313616763740ac
sha512: 331a85a83bb833581ed24a8b3549e1aea07bae5b443c7a088c83b9a4c59afe472ae8c326cd77781f7b2b72be09d92c1512418dd6dd8814aa264115742c01a582
ssdeep: 49152:1jI7CalwybqMG7bYK8bbls0TyIBWgeDKNK65DAyIDUr4ZEkCa9l714YwIGjg+AqS:1jkayb5yIBcD0rAyIDUu5vBD+Aq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192265C50FDDB90F5E6074A3049A7A37F2730A2099338CBD7CA545E96F817BE1097326A
sha3_384: 099b48caa7a259ce2e370a33eeefa097c78c650c931ea8c8c3e8d9aa276b6598bb8c221b3e08bfe3afc1b5316c021c74
ep_bytes: e9fbdaffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.2309432668 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.Heur3.LPT.@BW@ay2mx1kab
FireEyeGen:Trojan.Heur3.LPT.@BW@ay2mx1kab
McAfeeArtemis!628F5AD41794
CylanceUnsafe
SangforTrojan.Win32.Sabsik.ml
AlibabaTrojan:Win32/Snojan.712e29e1
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Heur3.LPT.EC87F7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.BJQQNDP
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Trojan.Heur3.LPT.@BW@ay2mx1kab
AvastWin32:Malware-gen
Ad-AwareGen:Trojan.Heur3.LPT.@BW@ay2mx1kab
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Trojan.rh
EmsisoftGen:Trojan.Heur3.LPT.@BW@ay2mx1kab (B)
IkarusTrojan.Crypt
AviraTR/Snojan.pabey
MAXmalware (ai score=85)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Ymacco.AA7E
GDataGen:Trojan.Heur3.LPT.@BW@ay2mx1kab
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.2223A0AE21
ALYacGen:Trojan.Heur3.LPT.@BW@ay2mx1kab
MalwarebytesMalware.AI.2309432668
TrendMicro-HouseCallTROJ_GEN.R002H0CB622
RisingTrojan.Snojan!8.E387 (CLOUD)
SentinelOneStatic AI – Suspicious PE
AVGWin32:Malware-gen
Cybereasonmalicious.417941
PandaTrj/CI.A
MaxSecureTrojan.Malware.73764767.susgen

How to remove Malware.AI.2309432668?

Malware.AI.2309432668 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment