Malware

Should I remove “Malware.AI.2624889440”?

Malware Removal

The Malware.AI.2624889440 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2624889440 virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a file
  • Creates a copy of itself
  • The sample wrote data to the system hosts file.

How to determine Malware.AI.2624889440?


File Info:

crc32: 70A0B5A7
md5: ebdccbc6a0440d6d8f7364d3d3624e61
name: EBDCCBC6A0440D6D8F7364D3D3624E61.mlw
sha1: f35ae6c58a8911f5b1987491ccaf336a5c7e7ff7
sha256: b9534139bc6ba111e8fe20874b8693e6402737a548507d803b0a0399242d2935
sha512: d5117d10013ae8946aab0f431cddae14136f6d433060cf9667ecfd8c46f6aa3b0331d72744453082f1203225d66f8f5a8a82a47ebf4db46644ace7542de5547a
ssdeep: 12288:GjkArEN249AyE/rbaMct4bO2/Vvt89b/jtns1LnmtHC8GlRzb:RFE//Tct4bOsVt89rjds1LnEHCdtb
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 6, 1
FileVersion: 3, 3, 6, 1
FileDescription:
Translation: 0x0809 0x04b0

Malware.AI.2624889440 also known as:

LionicTrojan.Win32.Dapato.lDsm
DrWebTrojan.Hosts.12905
ClamAVWin.Trojan.Autoit-185
ALYacAIT:Trojan.Nymeria.4006
CylanceUnsafe
ZillyaDropper.Dapato.Win32.13853
SangforHacktool.Win32.AutInject.CF
AlibabaRansom:Win32/Blocker.10bfa3e5
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:Decode-N [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.bgyn
BitDefenderAIT:Trojan.Nymeria.4006
NANO-AntivirusTrojan.Win32.Blackshades.brzdez
MicroWorld-eScanAIT:Trojan.Nymeria.4006
TencentWin32.Trojan.Blocker.Aojk
Ad-AwareAIT:Trojan.Nymeria.4006
SophosMal/Generic-S
ComodoMalware@#fu8brlb368gu
BitDefenderThetaAI:Packer.24ED534516
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Spyware.gc
FireEyeAIT:Trojan.Nymeria.4006
EmsisoftAIT:Trojan.Nymeria.4006 (B)
AviraHEUR/AGEN.1115129
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/AutInject.CF
GDataAIT:Trojan.Nymeria.4006 (3x)
AhnLab-V3Dropper/Win32.Dapato.R43144
McAfeeArtemis!EBDCCBC6A044
MAXmalware (ai score=100)
VBA32Trojan.Autoit.F
MalwarebytesMalware.AI.2624889440
PandaTrj/CI.A
RisingTrojan.Obfus/Autoit!1.C609 (CLASSIC)
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ADH!tr
AVGAutoIt:Decode-N [Trj]
Qihoo-360Win32/Ransom.Blocker.HwsBOBMA

How to remove Malware.AI.2624889440?

Malware.AI.2624889440 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment