Malware

Malware.AI.2541198329 removal guide

Malware Removal

The Malware.AI.2541198329 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2541198329 virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.2541198329?


File Info:

name: AF875EB005A3DCA0DAE2.mlw
path: /opt/CAPEv2/storage/binaries/711f340d1cd009b4efc7a0dfa7b3d243600a550f3a9821a294bcdb70f159b528
crc32: 400CA980
md5: af875eb005a3dca0dae2cc2cf2a1cca4
sha1: cc650f3f49cd1e3e1fc32dd073a576be4241873e
sha256: 711f340d1cd009b4efc7a0dfa7b3d243600a550f3a9821a294bcdb70f159b528
sha512: 80a4e389bebc06075e7409047209a8e2ea43b5d917f2fd3794d204aa74c651ec6e5c3ea2c22694cb84698cdebe087df3c07dc08fdec6bec527a9753e3d122fcc
ssdeep: 3072:WqEH+GiEs2SMylNOjyFbxJn5qolDe+CfO3UojYMJuJKw3HNVtiWTjzmJiYWvJmN9:LsehzRFHmL+YMJGKwtimzrX50C2d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A34F1135BEA847BE0F2A77099F6078327747CA6BC79633E039D688E4D321906578327
sha3_384: 20b199dd99b442daf59004c6fe1e5f63a70402799b3972d207ca467ac1b16f4b062ba128f3c6f209d3e2b03ce14aa6b2
ep_bytes: 558bec83ec4456ff155c1100018bf08a
timestamp: 2003-03-25 07:08:18

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.3790.0 (srv03_rtm.030324-2048)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.00.3790.0
Translation: 0x0409 0x04b0

Malware.AI.2541198329 also known as:

ClamAVWin.Trojan.KillAV-47
CAT-QuickHealTrojanDownloader.Small.BPQ4
McAfeeArtemis!AF875EB005A3
CylanceUnsafe
K7AntiVirusTrojan ( 0056d8931 )
BitDefenderMemScan:Trojan.GenericKDZ.81208
K7GWTrojan ( 0056d8931 )
Cybereasonmalicious.005a3d
BaiduWin32.Backdoor.Agent.n
CyrenW32/KillAV.AI.gen!Eldorado
SymantecW32.SillyDC
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Scar.boyzv
MicroWorld-eScanMemScan:Trojan.GenericKDZ.81208
RisingWorm.Citeary!1.D87E (CLASSIC)
Ad-AwareMemScan:Trojan.GenericKDZ.81208
SophosML/PE-A + Mal/Geral-A
ComodoSuspicious@#1d28x12g6sszh
DrWebTrojan.BrowseBan.565
VIPREMemScan:Trojan.GenericKDZ.81208
TrendMicroTROJ_DROPR.SMQV
McAfee-GW-EditionGenericRXFI-FV!6B4296A61E9E
Trapminemalicious.moderate.ml.score
FireEyeMemScan:Trojan.GenericKDZ.81208
SentinelOneStatic AI – Malicious SFX
JiangminTrojan/Scar.ahwc
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.2D
KingsoftWin32.Troj.Scar.cw.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-KillAV
GDataWin32.Trojan.Kryptik.6JDF8Q
AhnLab-V3Trojan/Win32.Pincav.R2875
BitDefenderThetaAI:Packer.D8A6618C1E
ALYacMemScan:Trojan.GenericKDZ.81208
TACHYONTrojan/W32.Scar.237056.B
VBA32Trojan.BrowseBan
MalwarebytesMalware.AI.2541198329
TrendMicro-HouseCallTROJ_DROPR.SMQV
TencentTrojan.Win32.Antiav.ya
YandexTrojan.GenAsa!4s2WNHwbfFs
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AntiAV.NFM!tr
AVGWin32:Geral [Trj]
AvastWin32:Geral [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.2541198329?

Malware.AI.2541198329 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment