Malware

Malware.AI.2470000364 removal

Malware Removal

The Malware.AI.2470000364 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2470000364 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Malware.AI.2470000364?


File Info:

crc32: D78FB794
md5: a2301c4f9d1dfd08a95bddf4b5329c7b
name: A2301C4F9D1DFD08A95BDDF4B5329C7B.mlw
sha1: ee2028f71eca2d6a20594ce2d58e10a870bc2d53
sha256: ac6207c5d791927225ae5901d11883c7525fbda42411c2be26c32733276603e7
sha512: dbb7b17dfd8002e1d028985a44fddac10c740f5bea11a64153dc74bbcc3f21f4f107bed04b2c76bf7ea57ec8a94b4f2c4c1ef00e782c360b9af8367a890d41d3
ssdeep: 1536:L9VArpS9UeKVVS4AgVFsUXlLWoRJUIjMGEl2lnlrwDLb0:L9VAro9UesjAgVFHR1s2lnlaLb0
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Malware.AI.2470000364 also known as:

K7AntiVirusTrojan ( 004f99a61 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.15562
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.MUE.A6
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f99a61 )
Cybereasonmalicious.f9d1df
CyrenW32/S-b5a1ff1e!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Goblinek [Inf]
KasperskyHEUR:Trojan-Ransom.Win32.Agent.pef
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Encoder.evgjti
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentWin32.Trojan.Agent.Ljjk
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.fy0@aWWFDKhQ
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-GJA!A2301C4F9D1D
FireEyeGeneric.mg.a2301c4f9d1dfd08
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bripg
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22C3AC7
MicrosoftRansom:Win32/Tovicrypt.A
SUPERAntiSpywareRansom.Cerber/Variant
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188553
Acronissuspicious
McAfeeRansomware-GJA!A2301C4F9D1D
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.2470000364
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.92 (RDML:daiKaO013IAb3o26+SU33w)
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Goblinek [Inf]
Paloaltogeneric.ml

How to remove Malware.AI.2470000364?

Malware.AI.2470000364 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment