Malware

Malware.AI.2402214388 removal

Malware Removal

The Malware.AI.2402214388 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2402214388 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2402214388?


File Info:

name: 5593C3120EEDF8110E57.mlw
path: /opt/CAPEv2/storage/binaries/bdbb9816bc090880b79bc8c9e6f26ce76ff0c9f3c48f8151c4df0b87f9aed4cb
crc32: 82BB4CB9
md5: 5593c3120eedf8110e57d6c024bb2558
sha1: e2f60b6b5e12c9ec465961f95e5283c480f5c7ef
sha256: bdbb9816bc090880b79bc8c9e6f26ce76ff0c9f3c48f8151c4df0b87f9aed4cb
sha512: 98ad23be0bf044a5c7c64eced78671e4362d54cb36a0f0dfb0139110aacfa29c0a1e91963be7055b08746eaa9bf19b842601e927f0e818c8ce0fa180e641ecfb
ssdeep: 1536:1spK+M/LVv0pBdQrAa/sOf5MFzF0K1/lex4vbLDuumW9I3iYIcuv9+xu73258Uf:L5xOOAa/lAFZbL7I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E14D7397707D4A5D119A53922F789BE71B3F45C4B87208F73886B626C60E089EB6F43
sha3_384: 482cc9a2d6a0d2ea3bd0e7b57f2fd4e4ff700aff3aa4f7d61777e998e217178ffc6025c44c832c71260b19821333aa74
ep_bytes: 6808134000e8f0ffffff000060000000
timestamp: 1996-10-28 02:27:01

Version Info:

0: [No Data]

Malware.AI.2402214388 also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.ct
McAfeeW32/Autorun.worm.aaeh
MalwarebytesMalware.AI.2402214388
VIPREGen:Variant.Zusy.473433
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Zusy.473433
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.b5e12c
BitDefenderThetaAI:Packer.DAA109BB1F
VirITTrojan.Win32.Vobfus.FBWF
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VBObfus.V
APEXMalicious
ClamAVWin.Malware.Vobfus-6793193-0
KasperskyTrojan.Win32.Jorik.Vobfus.fbwf
NANO-AntivirusTrojan.Win32.Jorik.coonis
MicroWorld-eScanGen:Variant.Zusy.473433
RisingWorm.Vobfus!8.10E (TFE:3:ODyxnaCmVFB)
TACHYONTrojan/W32.VB-Jorik.200704.N
SophosML/PE-A
BaiduWin32.Worm.Pronny.fp
F-SecureWorm.WORM/Vobfus.GJ.1
DrWebWin32.HLLW.Autoruner2.16029
TrendMicroTROJ_GEN.R011C0DJV23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5593c3120eedf811
EmsisoftGen:Variant.Zusy.473433 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.gwhv
WebrootW32.Worm.Go
GoogleDetected
AviraWORM/Vobfus.GJ.1
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.GO
ArcabitTrojan.Zusy.D73959
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fbwf
GDataWin32.Trojan.PSE.1OJHJNG
VaristW32/VB.HE.gen!Eldorado
AhnLab-V3Trojan/Win.Jorik.R524019
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Variant.Zusy.473433
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R011C0DJV23
TencentTrojan.Win32.Vobfus.kqq
IkarusVirus.Win32.Cryptor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:VBCrypt-BJA [Trj]
AvastWin32:VBCrypt-BJA [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2402214388?

Malware.AI.2402214388 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment