Malware

How to remove “Malware.AI.2664367298”?

Malware Removal

The Malware.AI.2664367298 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2664367298 virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Malware.AI.2664367298?


File Info:

name: 71C9583525654EE9C864.mlw
path: /opt/CAPEv2/storage/binaries/6cb723dff2652060cb867b8c892567cc39644141c9025d2d84a55c9e83f30875
crc32: 3BAE084B
md5: 71c9583525654ee9c864ae9f9fe09640
sha1: 3b3f8d4d47727346694357e2e7ccecf277a4e6c5
sha256: 6cb723dff2652060cb867b8c892567cc39644141c9025d2d84a55c9e83f30875
sha512: 2d13dc5a1f21f1b61245dc5c75ce88885f054e45ca4741fd76ab55c6d3281315f9e1c5a2dcff14f3270e64f25754bfcd8dce8bb5fbb2d334d3d379ba419a2eac
ssdeep: 12288:hkY6u3Kn9EoWpJbaq8l3th6XzVEp9H//5OsniJg70AbhVoY4AnL4R65:hkzk+OoWpJMh76jVEp9f/osvQA1qwN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132C582E5F335A50BFA11C1F04068BAF641507EEA431342CBB59DB9AD32F726E8C199C6
sha3_384: 83dea72b9a926ed298f6a9f36b95fcf1b9caff784f4c55cda194bc0fa2980060091e29e3b65bf6afaa8ec3f876b15d2f
ep_bytes: e892040000e936fdffff8bff558bec81
timestamp: 2012-05-19 12:05:04

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: Remote Desktop Connection
FileVersion: 6.1.7600.16385
InternalName: mstsc.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks: © Microsoft Corporation. All rights reserved.
OriginalFilename: mstsc.exe.mui
PrivateBuild: mstsc.exe.mui
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
SpecialBuild: 6.1.7600.16385
Translation: 0x0409 0x04b0

Malware.AI.2664367298 also known as:

DrWebTrojan.DownLoader6.16144
MicroWorld-eScanGen:Heur.Naffy.1
FireEyeGeneric.mg.71c9583525654ee9
ALYacGen:Heur.Naffy.1
CylanceUnsafe
VIPREGen:Heur.Naffy.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004e4f641 )
K7GWTrojan ( 004e4f641 )
Cybereasonmalicious.525654
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Rodecap.AR
APEXMalicious
ClamAVWin.Trojan.Multi-6413508-0
KasperskyHEUR:Trojan-Ransom.Win32.Blocker.gen
BitDefenderGen:Heur.Naffy.1
AvastWin32:Downloader-ONA [Trj]
Ad-AwareGen:Heur.Naffy.1
EmsisoftGen:Heur.Naffy.1 (B)
ComodoTrojWare.Win32.Downloader.Jorik.AO@4mxqf9
ZillyaTrojan.Jorik.Win32.174262
TrendMicroRansom_Blocker.R011C0DHL22
McAfee-GW-EditionMutopy-BAB!71C958352565
SophosMal/Generic-R + Troj/Dapato-A
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.Naffy.1
JiangminTrojan/Jorik.esha
GoogleDetected
AviraTR/Kazy.34213.jh
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.AB3
ArcabitTrojan.Naffy.1
ZoneAlarmHEUR:Trojan-Ransom.Win32.Blocker.gen
MicrosoftTrojan:Win32/Mutopy.A
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.BAB.C5049741
McAfeeMutopy-BAB!71C958352565
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.2664367298
TrendMicro-HouseCallRansom_Blocker.R011C0DHL22
RisingTrojan.Mutopy!1.9D89 (CLASSIC)
YandexTrojan.GenAsa!Go1jey9UezM
IkarusTrojan.Win32.Jorik
FortinetW32/Dapato.AA!tr
AVGWin32:Downloader-ONA [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.2664367298?

Malware.AI.2664367298 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment