Malware

Malware.AI.2349560357 removal

Malware Removal

The Malware.AI.2349560357 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2349560357 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Malware.AI.2349560357?


File Info:

name: 14ED2BC426F3B14D5896.mlw
path: /opt/CAPEv2/storage/binaries/00eda5249a2834f161fb48172c0a06cd676e6188586441668fa55e3b56e7a1e4
crc32: 2E1D048F
md5: 14ed2bc426f3b14d58969bb133d69f8e
sha1: ff4f23cba63c8dc15e7346fea2a2c45f4a507653
sha256: 00eda5249a2834f161fb48172c0a06cd676e6188586441668fa55e3b56e7a1e4
sha512: fdb3dd503a00ce06dc610373f3293d1524016b3386b2dcffaee526224c93e6dcc035bdd1e6bc61952a8f11aa21e3ca546c0b995494ed678ede988a1f308bfbe6
ssdeep: 384:/TSbTKzTrO96k/uCLliAOXJhVCW56lDAAzPfO96k/:/ear8HFiA2bVCW5sACf8H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130D2E7238AAC2572E55646B20E3707B809237CA46910DE0F5A6A6D6C3D35F537EF432F
sha3_384: 1ca2ab0b3a26d051750d7bf38bd2a2ecd5ec9aafbc55afc53463cddeee0e6f6056ded9692fb108c13902116e4ed52c3c
ep_bytes: 68241b4000e8f0ffffff000000000000
timestamp: 2012-01-10 22:03:44

Version Info:

Translation: 0x0c0a 0x04b0
Comments: Utilidad para navegar la Web y Pc
CompanyName: Dj_Dexter
FileDescription: Navegador de Web
LegalCopyright: (c)2007 Dj_Dexter
LegalTrademarks: Dj_Dexter S.A
ProductName: Navegador Web
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ADF45
OriginalFilename: ADF45.exe

Malware.AI.2349560357 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Variant.Razy.689196
FireEyeGen:Variant.Razy.689196
ALYacGen:Variant.Razy.689196
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
K7AntiVirusSpyware ( 005092db1 )
AlibabaTrojanClicker:Win32/Generic.0ab979fb
K7GWSpyware ( 005092db1 )
Cybereasonmalicious.426f3b
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanClicker.VB.OJI
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.689196
NANO-AntivirusTrojan.Win32.Click.esbpnr
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Razy.689196
SophosMal/Generic-S
ComodoMalware@#590nk5z4ee8g
VIPREGen:Variant.Razy.689196
McAfee-GW-EditionGenericRXLN-XU!14ED2BC426F3
EmsisoftGen:Variant.Razy.689196 (B)
IkarusTrojan.Win32.TrojanClicker
GDataGen:Variant.Razy.689196
AviraHEUR/AGEN.1206533
Antiy-AVLTrojan/Generic.ASMalwS.2C
ArcabitTrojan.Razy.DA842C
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeGenericRXLN-XU!14ED2BC426F3
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.2349560357
APEXMalicious
RisingTrojan.Clicker-VB!8.49 (CLOUD)
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.3E2D95
AVGWin32:Trojan-gen
PandaTrj/Chgt.AB
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.2349560357?

Malware.AI.2349560357 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment