Malware

Malware.AI.2476211069 removal instruction

Malware Removal

The Malware.AI.2476211069 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2476211069 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to identify installed AV products by installation directory
  • Operates on local firewall’s policies and settings
  • Deletes executed files from disk
  • Harvests information related to installed mail clients
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2476211069?


File Info:

name: 07A4F849057B855FFDE3.mlw
path: /opt/CAPEv2/storage/binaries/b8d2831c165c7c3b08e51b3221c79f6fc52c2ee8021edff236c613647d73b62d
crc32: 66A82D85
md5: 07a4f849057b855ffde391f935658e2a
sha1: 9b0086438dfc48c1a876e42cd5048e5186e9ec31
sha256: b8d2831c165c7c3b08e51b3221c79f6fc52c2ee8021edff236c613647d73b62d
sha512: be1001aa3b69d31caaefe6e0142d162e64f8e09cc02e1a00fff4f4fdecb4a7d6def311d9f9b17a73a7609647a759c201455e303ab1cee0c869ffdc3c4a6b51cb
ssdeep: 6144:h/0uo6eKguxTOPbEwmznc8srkXnHJsxNsAB0ANaQUmbScyuEzx+P3LduHV:hJ4yV4mznQk3CHsARhUyLay3k1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170A4120382E2C177C0D403F446DA6673137ABCE87B4A63AB92CE49E99D613C5A67D31D
sha3_384: 84c02673a554867b46205dd5e1fb931b10ae174b7f54df32fba3a084e37e1078c0ce285b9e3c46d80ef4b31555450866
ep_bytes: e80a000000e97affffffcccccccccc8b
timestamp: 2008-04-13 18:32:45

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
InternalName: Wextract
LegalCopyright: (C)Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.00.2900.5512
Translation: 0x0412 0x04b0

Malware.AI.2476211069 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader1.6751
MicroWorld-eScanMemScan:Trojan.Dropper.Agent.UYS
ClamAVWin.Dropper.Agent-35943
McAfeeArtemis!07A4F849057B
MalwarebytesMalware.AI.2476211069
K7AntiVirusTrojan ( 000ab86d1 )
K7GWTrojan ( 000ab86d1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.FCF08A541F
VirITTrojan.Win32.Dnldr1.JZR
CyrenW32/Prolaco.OCMR-2495
SymantecW32.Ackantta!Dr
ESET-NOD32Win32/Merond.O
ZonerTrojan.Win32.1791
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Dropper.Win32.Typic.bef
BitDefenderMemScan:Trojan.Dropper.Agent.UYS
NANO-AntivirusTrojan.Win32.Typic.bdago
AvastWin32:Malware-gen
EmsisoftMemScan:Trojan.Dropper.Agent.UYS (B)
F-SecureSuspicious:W32/Executable.A
VIPREMemScan:Trojan.Dropper.Agent.UYS
TrendMicroWORM_PROLACO.HD
McAfee-GW-EditionW32/Routrobot.a
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.07a4f849057b855f
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious SFX
GDataWin32.Trojan.Prolaco.A
JiangminTrojanDropper.Typic.ml
AviraWORM/Prolaco.C.7
MAXmalware (ai score=83)
Antiy-AVLTrojan[Dropper]/Win32.Typic
XcitiumMalware@#1j3gcnu07sebu
ArcabitTrojan.Dropper.Agent.UYS
ZoneAlarmTrojan-Dropper.Win32.Typic.bef
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32TrojanDropper.Typic
ALYacMemScan:Trojan.Dropper.Agent.UYS
TACHYONBackdoor/W32.Hupigon.460800.H
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallWORM_PROLACO.HD
RisingTrojan.Detplock!8.4A0D (TFE:5:C8nTonNNsxN)
IkarusWorm.Win32.Prolaco
MaxSecureVirus.W32.Cabres.a
FortinetW32/Merond.O!worm
AVGWin32:Malware-gen
Cybereasonmalicious.38dfc4
DeepInstinctMALICIOUS

How to remove Malware.AI.2476211069?

Malware.AI.2476211069 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment