Malware

What is “Malware.AI.2657435372”?

Malware Removal

The Malware.AI.2657435372 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2657435372 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Malware.AI.2657435372?


File Info:

name: 0328FEDC8EB24E4CFF7B.mlw
path: /opt/CAPEv2/storage/binaries/d8a383d00109c6a4406fa75809e108400d0599561f062bb4722d58c5ffcb7eb6
crc32: BD85A1B3
md5: 0328fedc8eb24e4cff7ba4056901f7c6
sha1: def6a1dd5ea80913355f39607e9e42aa133bf732
sha256: d8a383d00109c6a4406fa75809e108400d0599561f062bb4722d58c5ffcb7eb6
sha512: a0ddbd62096375ae016f44432ccc4aebde44efdd021480fb51869d3b4f7cc58307099d9bd9eea2c51b5b9bfe88eef1153ae62dc939f4971f36e915a8187e25b7
ssdeep: 192:whn5+9kyQeSzbgEEyZs8FatDCXHHjDb3KN8P3EWT+Y:Yn3eSzbkyZBmCXnjDzKKP3EWT+Y
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T119F1B302E3FDC115F5FE4F7628B227100A76FE871852D26E688480196E31B59CAA1BB7
sha3_384: a227beb1ea025827cd3c98c0460cbe3601e4d53ee3bd69030c7937e0798ccbb09f8f32c66ab63886c82e61c0a4e0e8e5
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-07-16 13:23:33

Version Info:

Translation: 0x0000 0x04b0
Comments: Shell Infrastructure Host
FileDescription: Shell Infrastructure Host
FileVersion: 10.0.19041.746
InternalName: DriverUpdate-watchdog.exe
LegalCopyright: © Microsoft Corporation. All Rights Reserved.
OriginalFilename: DriverUpdate-watchdog.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.746
Assembly Version: 0.0.0.0

Malware.AI.2657435372 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MinerNET.23
MicroWorld-eScanGen:Variant.Bulz.563083
FireEyeGeneric.mg.0328fedc8eb24e4c
McAfeeArtemis!0328FEDC8EB2
K7AntiVirusTrojan ( 0057fd7f1 )
AlibabaTrojan:Win32/CoinMiner.1e77c009
K7GWTrojan ( 0057fd7f1 )
CrowdStrikewin/malicious_confidence_80% (W)
CyrenW64/MSIL_Coinminer.C.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/CoinMiner.CGV
TrendMicro-HouseCallTROJ_GEN.R067C0DH621
Paloaltogeneric.ml
ClamAVWin.Trojan.Bulz-9879448-0
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderGen:Variant.Bulz.563083
AvastWin64:Trojan-gen
TencentWin32.Trojan.Coinminer.Bxo
Ad-AwareGen:Variant.Bulz.563083
EmsisoftGen:Variant.Bulz.563083 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0DH621
SophosMal/Generic-S
IkarusTrojan.Win32.CoinMiner
AviraHEUR/AGEN.1143065
MAXmalware (ai score=80)
MicrosoftTrojan:MSIL/Coinminer.GA!MTB
GDataGen:Variant.Bulz.563083
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Trojan-gen.C4553928
ALYacGen:Variant.Bulz.563083
MalwarebytesMalware.AI.2657435372
SentinelOneStatic AI – Malicious PE
FortinetAdware/Miner
AVGWin64:Trojan-gen
PandaTrj/CI.A

How to remove Malware.AI.2657435372?

Malware.AI.2657435372 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment