Malware

About “Malware.AI.2616049395” infection

Malware Removal

The Malware.AI.2616049395 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2616049395 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.2616049395?


File Info:

name: 3E6310CC80CC8496DA5C.mlw
path: /opt/CAPEv2/storage/binaries/29743a7559422a1e8497b4b5c53e00cfb1d420be9f0301578f55f4622f1ab9ab
crc32: 25BCC9B7
md5: 3e6310cc80cc8496da5c8e9974e4d4a8
sha1: 0b5296ffef43b5d752a4f9ccd0d9a782a5e28a0b
sha256: 29743a7559422a1e8497b4b5c53e00cfb1d420be9f0301578f55f4622f1ab9ab
sha512: 1c03647a337a5f6b19b05f2cd32939b646b23eb9f198e686a9433654b887dbd5a723617c0bcd1b779f647dd5dd7300252043baa56938b115acfbaebf98d2115f
ssdeep: 1536:qQpQ5EP0nEbaByITXJIVN5cQ8IvCUSyuzFqvLl:qQIdyITXJI+Q1vCbzmLl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144338D5636C0C8B3D8678631DE639BF6D7B9FF05E5A1152B2B903FBE35320929606243
sha3_384: cc36a5c07b801e4eceb528ea5125356da03bb2a2e385fd73072e0f6e3f7779659bae62bbbfd79c8ff8c69e8d493c7813
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Malware.AI.2616049395 also known as:

MicroWorld-eScanGen:Variant.Application.Bundler.Outbrowse.15
ClamAVWin.Trojan.15053624-1
FireEyeGeneric.mg.3e6310cc80cc8496
CAT-QuickHealTrojandownloader.Subroate.A5
McAfeeGenericR-FMG!76B0086DD791
MalwarebytesMalware.AI.2616049395
CrowdStrikewin/grayware_confidence_100% (D)
K7GWAdware ( 004d4c5e1 )
K7AntiVirusAdware ( 004d4c5e1 )
CyrenW32/S-2d592e79!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/IStartSurf.A potentially unwanted
CynetMalicious (score: 99)
Kasperskynot-a-virus:Downloader.Win32.AdLoad.rcug
BitDefenderGen:Variant.Application.Bundler.Outbrowse.15
NANO-AntivirusTrojan.Win32.AdLoad.dxdazc
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Application.Bundler.Outbrowse.15 (B)
F-SecureTrojan.TR/Graftor.pqiflug
DrWebTrojan.Vittalia.800
VIPREGen:Variant.Application.Bundler.Outbrowse.15
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.qh
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
GDataWin32.Trojan.PSE.1K42MKH
JiangminVariant.Kazy.qs
AviraHEUR/AGEN.1345547
Antiy-AVLGrayWare[Adware]/Win32.istartsurf.a
XcitiumTrojWare.Win32.Graftor.DK@5uujkt
ArcabitTrojan.Application.Bundler.Outbrowse.15
ZoneAlarmHEUR:Trojan-Downloader.Win32.Small.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36132.bu4@auBgk6ai
ALYacGen:Variant.Application.Bundler.Outbrowse.15
MAXmalware (ai score=76)
VBA32Downloader.AdLoad
Cylanceunsafe
RisingAdware.IStartSurf!1.A35C (CLASSIC)
YandexPUA.Downloader!EdlSNQ9TLOM
IkarusTrojan.Kazy
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Small.DGQQ!tr.dldr
AVGWin32:Evo-gen [Trj]

How to remove Malware.AI.2616049395?

Malware.AI.2616049395 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment