Malware

What is “Malware.AI.2458588002”?

Malware Removal

The Malware.AI.2458588002 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2458588002 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2458588002?


File Info:

name: 49C37B6170EC673A7153.mlw
path: /opt/CAPEv2/storage/binaries/bc674bceb3e24de7d9e93671365f5597e2524d8deb424570169c75f68919e59f
crc32: 3EF6C86E
md5: 49c37b6170ec673a7153aa334ce32687
sha1: a979b8fdb22a2fee1d72a1f6ff9a25b619acdd41
sha256: bc674bceb3e24de7d9e93671365f5597e2524d8deb424570169c75f68919e59f
sha512: 79cd7b5ba5761cf5d7169b63158a8d1627a429808e5a5b21bcd07c5c4aed4b41a5746842d8679152f50307171b6d3e7ec021e7d8cdcf2959277077c550e49cff
ssdeep: 6144:UBcdXNFg0MdxjLqlvDD/CRXTxdOsnI93DAhxnqd706TFKQufWhezMmkT5RAwCBM0:yBPSa7xw4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189E457602FB7D125F2B79F3AC6E471C72A7B77935C68510A2395A1181233A4EC9F1E32
sha3_384: cefc39acf7b027e70e44eb68b06614b6ebf9bf83a6c109db533c45319b7f4ce8e0aa2c5e938e10e5c4fb470aea6b8552
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-02-12 20:51:13

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: x822y.exe
LegalCopyright:
OriginalFilename: x822y.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Malware.AI.2458588002 also known as:

LionicVirus.MSIL.Lamer.n!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.94672
ClamAVWin.Packed.Barys-7725442-0
FireEyeGeneric.mg.49c37b6170ec673a
CAT-QuickHealW32.Lamer.M3
ALYacTrojan.GenericKDZ.94672
Cylanceunsafe
ZillyaTrojan.RibajGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00544e311 )
AlibabaVirus:MSIL/CryptInject.24cd2c23
K7GWTrojan ( 00544e311 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Ribaj.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Ribaj.D
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Virus.MSIL.Lamer.gen
BitDefenderTrojan.GenericKDZ.94672
BitDefenderThetaGen:NN.ZemsilF.36302.Qm3@aWLJmXi
SUPERAntiSpywareTrojan.Agent/Gen-Ribaj
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Virus.Ribaj.Psmw
TACHYONWorm/W32.MSILamer
SophosMSIL/Ribaj-A
F-SecureTrojan.TR/Dropper.Gen
DrWebMSIL.Cola.1
VIPRETrojan.GenericKDZ.94672
TrendMicroVirus.MSIL.RIBAJ.SMW
McAfee-GW-EditionBehavesLike.Win32.Suspicious.jt
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKDZ.94672 (B)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Virus.Ribaj.B
JiangminVirus.MSIL.Lamer.a
AviraTR/Dropper.Gen
Antiy-AVLTrojan/MSIL.Ribaj.a
XcitiumVirus.MSIL.Ribaj.F@7oybry
ArcabitTrojan.Generic.D171D0
ZoneAlarmHEUR:Virus.MSIL.Lamer.gen
MicrosoftVirTool:MSIL/CryptInject.YA!MTB
GoogleDetected
AhnLab-V3Win32/Ribaj.X1979
Acronissuspicious
McAfeeGenericRXAO-XB!49C37B6170EC
MAXmalware (ai score=82)
VBA32Virus.MSIL.Lamer.1
MalwarebytesMalware.AI.2458588002
PandaTrj/CI.A
TrendMicro-HouseCallVirus.MSIL.RIBAJ.SMW
RisingTrojan.Ribaj!1.B577 (CLASSIC)
YandexTrojan.Agent!A5qzeRd3nZ0
IkarusVirus.MSIL.CryptInject
MaxSecureTrojan.generickdz.51307
FortinetMSIL/Ribaj.D
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.2458588002?

Malware.AI.2458588002 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment