Malware

What is “Malware.AI.2441685428”?

Malware Removal

The Malware.AI.2441685428 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2441685428 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location

Related domains:

wpad.local-net

How to determine Malware.AI.2441685428?


File Info:

name: 4C34C083F8E6C8EDCC5C.mlw
path: /opt/CAPEv2/storage/binaries/cf62b7dda2bc0468140dfdcb14bfe9f4a71ca5a9e46b5dcd597ca802ba422169
crc32: 75B9DBC4
md5: 4c34c083f8e6c8edcc5cb57a30da255a
sha1: 654eb003dda5c7809c85d6dc8add63e6d8d01b28
sha256: cf62b7dda2bc0468140dfdcb14bfe9f4a71ca5a9e46b5dcd597ca802ba422169
sha512: 05c570f41c1bc48fd14133ef3ddaa8f084807758d9578f2ff65c12e748490fa7da976114cdb6fc8e7de77cb68878f4c9965b02f96e70416cbefb8dfe8d92b9c9
ssdeep: 49152:Y7GEebazPAMOSUQ5O/77NzoelD1JsWJJQ8Cp1omsUNew46JbIXaZhE5HS:Y7GJ+UBSnO/n2elD13rQZrLyaZhEs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2C533AB5F8718A9CE93683D0A17DB8994B995873681DFF7DE1402BC84E4340A3531EF
sha3_384: 08fbb4026011e50531b14df53e921d3549bb0c03250874d9482e224da383482bccc2dcd05818464131028738bfdeb52d
ep_bytes: 60be003042008dbe00e0fdff5789e58d
timestamp: 2011-07-18 11:56:29

Version Info:

0: [No Data]

Malware.AI.2441685428 also known as:

MicroWorld-eScanTrojan.GenericKD.38123516
FireEyeTrojan.GenericKD.38123516
ALYacTrojan.GenericKD.38123516
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.38123516
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D245B7FC
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/Rozena.BN
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Rozena.677cd567
TencentMalware.Win32.Gencirc.11c16e18
Ad-AwareTrojan.GenericKD.38123516
EmsisoftTrojan.GenericKD.38123516 (B)
ZillyaTrojan.Generic.Win32.378062
McAfee-GW-EditionBehavesLike.Win32.Downloader.vc
SophosMal/Generic-S
AviraTR/AD.Swrort.asbey
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Backdoor.Rozena.JGYK9I
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4500091
McAfeeGenericRXAA-AA!4C34C083F8E6
MAXmalware (ai score=84)
MalwarebytesMalware.AI.2441685428
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R035C0GKR21
YandexTrojan.Agent!QOMjDCvo4G0
IkarusTrojan.Python.Rozena
FortinetW32/Rozena.BN!tr
AVGWin32:GenMalicious-DVD [Trj]
AvastWin32:GenMalicious-DVD [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2441685428?

Malware.AI.2441685428 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment