Malware

About “Malware.AI.245943340” infection

Malware Removal

The Malware.AI.245943340 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.245943340 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Malware.AI.245943340?


File Info:

name: 99EF0ACBFF44830ACB14.mlw
path: /opt/CAPEv2/storage/binaries/c2b8b0f95eebfb0ee5d1297c4ba5bd2da54ad7cc8add7ae0d85ce09dd2f30c1a
crc32: AD6D4549
md5: 99ef0acbff44830acb1474cf365db691
sha1: 247bd249db3d491dcc2bcdb8fec73fd7fedbc258
sha256: c2b8b0f95eebfb0ee5d1297c4ba5bd2da54ad7cc8add7ae0d85ce09dd2f30c1a
sha512: 18198f1945a5f3ec697fa7541c538fec7ece647ceb479612e960a443e4ba9f5c3abc0b8c93186a5bd6f1dae0bf3ad065a82e782d272789aef2f93a6b67c8fa28
ssdeep: 6144:YT0UlF2vH7kK0yOQs9brFP23XVSOUBqKM6R1zJC6DMVu31uhorU+hShLpwAElA7n:YTJlwvbj01rt21rUBqKM8boNi+pwAEE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180C4D0A33803682CC94906B50166D0F0F7739F967AA08E0DB0DA7F1B3E3275B674566E
sha3_384: 3e430cdba3dc9a349f4493ead3373484897a091b20ea45e9df5fd1e244a7d58ef6a14b41fd478d9d318131c6c309e709
ep_bytes: ff250020400000000000000000000000
timestamp: 2009-12-16 12:37:50

Version Info:

Translation: 0x0000 0x04b0
Comments: by AnubisGod
CompanyName: Anubis
FileDescription: Anubis Auto update
FileVersion: 1.0.0.0
InternalName: AutoUpdate1.exe
LegalCopyright: Copyright © 2008 - 2019. All rights reserved.
OriginalFilename: AutoUpdate1.exe
ProductName: Anubis Auto-Update
ProductVersion: 1.0.0.0
Assembly Version: 0.0.0.0

Malware.AI.245943340 also known as:

LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Benin.3
FireEyeGeneric.mg.99ef0acbff44830a
ALYacGen:Heur.MSIL.Benin.3
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1094328
SangforTrojan.MSIL.Agent.aeada
K7AntiVirusTrojan ( 00545ecf1 )
AlibabaTrojan:MSIL/Kryptik.fcfc8200
K7GWTrojan ( 00545ecf1 )
Cybereasonmalicious.bff448
ArcabitTrojan.MSIL.Benin.3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.QPE
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.MSIL.Agent.aeada
BitDefenderGen:Heur.MSIL.Benin.3
NANO-AntivirusTrojan.Win32.Inject3.fmkdej
AvastWin32:Trojan-gen
Ad-AwareGen:Heur.MSIL.Benin.3
ComodoMalware@#20ni7gc42ay00
DrWebTrojan.Inject3.12248
TrendMicroBKDR_HPBLADABINDI.SMZ
McAfee-GW-EditionBehavesLike.Win32.Fareit.hc
EmsisoftGen:Heur.MSIL.Benin.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.lhgn
AviraHEUR/AGEN.1101621
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2A6C458
MicrosoftTrojan:Win32/Tiggre!rfn
GDataGen:Heur.MSIL.Benin.3
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.ADH.C78592
Acronissuspicious
McAfeePacked-FPW!99EF0ACBFF44
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.245943340
TrendMicro-HouseCallBKDR_HPBLADABINDI.SMZ
TencentWin32.Trojan.Inject.Auto
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.QRG!tr
BitDefenderThetaGen:NN.ZemsilF.34294.Hm0@aeMiW8m
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Malware.AI.245943340?

Malware.AI.245943340 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment