Malware

Malware.AI.2706336485 removal

Malware Removal

The Malware.AI.2706336485 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2706336485 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Greek
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.2706336485?


File Info:

name: 2657FEEAE46B5FF27254.mlw
path: /opt/CAPEv2/storage/binaries/491473ecf139fc3f3ed46461e765f8ede595ff2f830e41907d3840bb6ed06a71
crc32: C0E7DABC
md5: 2657feeae46b5ff2725404c04ebfbef2
sha1: 33acd9ff3ce9a8c760d560cf6c8e3e121c1dd21a
sha256: 491473ecf139fc3f3ed46461e765f8ede595ff2f830e41907d3840bb6ed06a71
sha512: fec6d1e87f52a262f26a5cbc6bea93f1507fff57c3f5997abffa2e84b76501323d9cc83392c00cfbc525f5a80dec37c49e772b6c74006c3e2ebe181eccb1ce28
ssdeep: 24576:SQg/5BSibbFJQXdIYjpVF7Ejbic44dpFdeWyWnlnSc9VhTg:pXnMFHdYWBnlSc9PTg
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1DB651762D6FC18D5C4F6C1B9C6636216B8B1BC498326F7E352585B1F0B2ABD0DB2E740
sha3_384: bae85e7d71cb74d27295dab8555a409d71cd71f2a28ccb22ff7f906a510a5f94c7ffc5b8d0c609ec6341de51eb284080
ep_bytes: 4883ec28e8df0500004883c428e976fe
timestamp: 2019-01-18 06:30:13

Version Info:

CompanyName: OmegaPawn.
FileDescription: OmegaPawn
FileVersion: 1.0.0.1
InternalName: omegapawn.exe
LegalCopyright: OmegaPawn. 2019
OriginalFilename: omegapawn.exe
ProductName: OmegaPawn
ProductVersion: 1.0.0.1
Translation: 0x0408 0x04b0

Malware.AI.2706336485 also known as:

LionicRiskware.Win64.CoinMiner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.BitCoinMiner.IdleBuddy.2
McAfeeArtemis!2657FEEAE46B
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRiskWare:Win64/CoinMiner.c6925525
Cybereasonmalicious.ae46b5
CyrenW64/Application.SRQR-0768
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Adware.OpenSUpdater.A
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win64.CoinMiner.gen
BitDefenderGen:Variant.Application.BitCoinMiner.IdleBuddy.2
AvastWin64:AdwareX-gen [Adw]
TencentWin32.Trojan.Falsesign.Hqbv
Ad-AwareGen:Variant.Application.BitCoinMiner.IdleBuddy.2
EmsisoftGen:Variant.Application.BitCoinMiner.IdleBuddy.2 (B)
VIPREWin64.Adware.OpenSUpdater
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.2657feeae46b5ff2
SophosGeneric PUA DD (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Application.BitCoinMiner.IdleBuddy.2
AviraHEUR/AGEN.1108436
MAXmalware (ai score=71)
Antiy-AVLGrayWare[AdWare]/Win64.OpenSUpdater
GridinsoftRansom.Win64.Gen.sa
ViRobotAdware.Opensupdater.1501248
MicrosoftPUADlManager:Win32/OpenDownloadManager
CynetMalicious (score: 100)
AhnLab-V3PUP/Win64.Generic.R369850
Acronissuspicious
ALYacGen:Variant.Application.BitCoinMiner.IdleBuddy.2
MalwarebytesMalware.AI.2706336485
TrendMicro-HouseCallTROJ_GEN.R002H0CJS21
YandexPUA.OpenSUpdater!3bSrey9ghiE
IkarusAdWare.Opensupdater
FortinetRiskware/CoinMiner
AVGWin64:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.2706336485?

Malware.AI.2706336485 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment