Malware

Malware.AI.2506370492 malicious file

Malware Removal

The Malware.AI.2506370492 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2506370492 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2506370492?


File Info:

name: CC9F1D15E24EBF26F44F.mlw
path: /opt/CAPEv2/storage/binaries/7ed5e2f3bce037c291e3c7469e131788024fd610d92445ee7bc6d0a299371657
crc32: A91C890F
md5: cc9f1d15e24ebf26f44f63c38ac7b6de
sha1: c9c1d81b19e5c6893a4ce280687989f1dec4d6da
sha256: 7ed5e2f3bce037c291e3c7469e131788024fd610d92445ee7bc6d0a299371657
sha512: 2770776e3fca762f619376287a4f4eadbcab39b08282343bdd577aa9f67902b6a195b5a00723f74f5da91d6549effc7841abe6a41bef25c6764d5ac1baef72a4
ssdeep: 12288:/Fh1TIvLx5QmTDthgD1ZCiPLwQlmNbHHqZTAxB:9TIvL84tiZwQAlHHqZT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AAF49C4277E99135F6F35B31AE7992515A7ABC729C39C20F23D41A1D08B0A90EA74F33
sha3_384: 97ee836df21924806fb1683fd55b701788005f053e30a01c5ec3f45138bcbd76ff44be40a97a8bc71266043e6436de6d
ep_bytes: e860230000e97ffeffff3b0da0154500
timestamp: 2018-09-20 06:36:28

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Bootstrapper for Single Installation
FileVersion: 19.8.20071.303822
InternalName: Setup.exe
LegalCopyright: Copyright © 2018 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: Setup.exe
ProductName: Bootstrapper Small
ProductVersion: 19.8.20071.303822
Translation: 0x0409 0x04e4

Malware.AI.2506370492 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Emotet.L!c
MicroWorld-eScanGen:Variant.Zusy.487862
SkyhighBehavesLike.Win32.Backdoor.bc
McAfeeRDN/Generic BackDoor
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
BitDefenderGen:Variant.Zusy.487862
K7GWTrojan ( 005ab4bf1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D771B6
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Senoval.a
AlibabaTrojan:Win32/Senoval.cace89bb
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
RisingTrojan.Generic@AI.100 (RDML:gsAoO/GQ8afBXN0zlrBcbA)
EmsisoftGen:Variant.Zusy.487862 (B)
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Beetle.2
TrendMicroTROJ_GEN.R002C0DJF23
FireEyeGeneric.mg.cc9f1d15e24ebf26
SophosW32/Patched-CE
IkarusTrojan.Win32.Patched
VaristW32/Patched.GS.gen!Eldorado
AviraTR/Patched.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Patched
MicrosoftTrojan:Win32/Doina.RPX!MTB
ZoneAlarmVirus.Win32.Senoval.a
GDataWin32.Trojan.PSE.11GD2R1
GoogleDetected
AhnLab-V3Malware/Win.Generic.R603715
BitDefenderThetaAI:Packer.5B17D7301F
ALYacGen:Variant.Zusy.487862
VBA32BScope.TrojanDownloader.Emotet
MalwarebytesMalware.AI.2506370492
TrendMicro-HouseCallTROJ_GEN.R002C0DJF23
TencentTrojan.Win32.Pathced_ya.16001052
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IP!tr
AVGWin32:Patched-AWW [Trj]
Cybereasonmalicious.b19e5c
DeepInstinctMALICIOUS

How to remove Malware.AI.2506370492?

Malware.AI.2506370492 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment