Malware

About “Malware.AI.2478622112” infection

Malware Removal

The Malware.AI.2478622112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2478622112 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2478622112?


File Info:

name: 106234C7EAC7C92AA2C1.mlw
path: /opt/CAPEv2/storage/binaries/8fb335935b42cea1aecd27afeb2a608d053c6af905d63bdc573db3921bdefac3
crc32: A814CA6D
md5: 106234c7eac7c92aa2c1992c22ee7619
sha1: bb4f1f87fe5274fd2c3e4f8b92daeb9e5398e2c8
sha256: 8fb335935b42cea1aecd27afeb2a608d053c6af905d63bdc573db3921bdefac3
sha512: c28ee8adfa39abf60db34a94a18dea97e61781e4a491fdf17226d10496fb320c2e162ab251f47eb91084e4380db65ee9f144ecd2c11c18be43a87033b74fc59a
ssdeep: 12288:TLI5J/TJD0GO+thSyVi/dKDK58Rg6veKZMU:TLI5J/TN0p+thSWi/dKDbRTveKZMU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AD94A61372219492E1555BFA63A743387AB8975138F4CD23FFE4DC72ACB1522871EA0E
sha3_384: be49ceec21ca633c109551f8f6e81630c8c6f438b4d82d500d9858be893a2524d0f75dd5839c8b774a2fc02d1a03cc50
ep_bytes: e82b4b0400e8f731040033c0c3909090
timestamp: 2015-07-16 11:07:16

Version Info:

0: [No Data]

Malware.AI.2478622112 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scar.mip4
tehtrisGeneric.Malware
CynetMalicious (score: 100)
CAT-QuickHealTrojan.ScarPMF.S23005079
McAfeePWS-FCCD!106234C7EAC7
MalwarebytesMalware.AI.2478622112
VIPREDeepScan:Generic.Dacic.EA08C894.A.9B8EEAEE
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 004baf591 )
AlibabaMalware:Win32/km_241a0.None
K7GWPassword-Stealer ( 004baf591 )
Cybereasonmalicious.7eac7c
BaiduWin32.Trojan-PSW.QQPass.ag
CyrenW32/S-e9acf57d!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.QQPass.OVQ
APEXMalicious
ClamAVWin.Adware.Razy-9853577-0
KasperskyTrojan.Win32.Scar.kvlm
BitDefenderDeepScan:Generic.Dacic.EA08C894.A.9B8EEAEE
NANO-AntivirusTrojan.Win32.Scar.duqmpl
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanDeepScan:Generic.Dacic.EA08C894.A.9B8EEAEE
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Scar.xe
EmsisoftDeepScan:Generic.Dacic.EA08C894.A.9B8EEAEE (B)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.DownLoader15.53353
ZillyaTrojan.Scar.Win32.99114
TrendMicroTROJ_GEN.R002C0DEN23
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.106234c7eac7c92a
SophosTroj/PWS-CJK
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11NFXRK
JiangminTrojan/Scar.blug
AviraADWARE/Adware.Gen
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitDeepScan:Generic.Dacic.EA08C894.A.9B8EEAEE
ZoneAlarmTrojan.Win32.Scar.kvlm
MicrosoftPWS:Win32/QQPass.GP
GoogleDetected
AhnLab-V3Trojan/Win32.Stealer.R143066
BitDefenderThetaGen:NN.ZexaF.36196.AqY@aaD3Vbe
ALYacDeepScan:Generic.Dacic.EA08C894.A.9B8EEAEE
MAXmalware (ai score=87)
VBA32Trojan.Scar
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEN23
RisingTrojan.QQPass!1.E2B0 (CLASSIC)
IkarusTrojan-PSW.QQpass
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zusy.307491!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2478622112?

Malware.AI.2478622112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment