Malware

How to remove “Malware.AI.2495798985”?

Malware Removal

The Malware.AI.2495798985 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2495798985 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:666
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempted to write directly to a physical drive

How to determine Malware.AI.2495798985?


File Info:

name: 9542634F393066BFA7A9.mlw
path: /opt/CAPEv2/storage/binaries/a26be4593d481a6c145440deca451c4132ec074ce57543ca87747d1ff460f2f0
crc32: 95C6C385
md5: 9542634f393066bfa7a9b68cb2f54057
sha1: b3b9efa3f917995b960f5017d0708a369eb82002
sha256: a26be4593d481a6c145440deca451c4132ec074ce57543ca87747d1ff460f2f0
sha512: 158130296a5ca26633f3b6031a46ae35f2bed1ac0efd3877869d8bd1fefb7035f57c714d601a883b69caacbf23fb34a81db9ce402ee8622852f42fd77730bf5f
ssdeep: 12288:8FwOTPclzRB0zolQwu7J6Yvb1REL9ikuK88a61GRv/:YTclza3kobfEL90r8aRRv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B356B27F3929837C5731A748C1B82B5A836BE102E3898563BF95E0C5F396817D352E7
sha3_384: e65647149efbeecf446ae9a199f94e152ceb92f5f444cfd2f3aed09aa35187047b8a623cdc64280ea849d829f5b16ef3
ep_bytes: 558bec83c4f4b8f8a44b00e898d0f4ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription: lock protection server
FileVersion: 2.8.3.2
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 24.0 (10/07/2004)
Comments:
Translation: 0x0404 0x03b6

Malware.AI.2495798985 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Aiqv.4!c
MicroWorld-eScanGen:Trojan.Malware.bj0@aiqV@7cb
McAfeeArtemis!9542634F3930
CylanceUnsafe
SangforTrojan.Win32.Occamy.CA2
AlibabaTrojan:Win32/Banker.7aae651e
Cybereasonmalicious.f39306
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Trojan.Malware.bj0@aiqV@7cb
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Trojan.Malware.bj0@aiqV@7cb
SophosML/PE-A
ComodoTrojWare.Win32.Kryptik.~NT@1r0f0f
McAfee-GW-EditionBehavesLike.Win32.Pluto.tm
FireEyeGeneric.mg.9542634f393066bf
EmsisoftGen:Trojan.Malware.bj0@aiqV@7cb (B)
IkarusTrojan-Banker.Win32.Bancos
GDataGen:Trojan.Malware.bj0@aiqV@7cb
AviraTR/Patched.Ren.Gen2
MAXmalware (ai score=99)
ArcabitTrojan.Malware.EB75EA
MicrosoftTrojan:Win32/Occamy.CA2
CynetMalicious (score: 99)
ALYacGen:Trojan.Malware.bj0@aiqV@7cb
MalwarebytesMalware.AI.2495798985
TrendMicro-HouseCallTROJ_GEN.R002H0CES21
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.118394238.susgen
AVGWin32:Evo-gen [Susp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Malware.AI.2495798985?

Malware.AI.2495798985 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment