Malware

Malware.AI.2708552709 removal tips

Malware Removal

The Malware.AI.2708552709 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2708552709 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Detects VMware through the presence of a registry key
  • Harvests credentials from local FTP client softwares

How to determine Malware.AI.2708552709?


File Info:

name: 7C0FD827CD7CE968A637.mlw
path: /opt/CAPEv2/storage/binaries/2e873acd0b8ae423390298c825c6af41a6b1f501d8aa96dcc549887d93de49f1
crc32: AD79F118
md5: 7c0fd827cd7ce968a6372502b4d9746f
sha1: 4cdd9d2a6c76a8673786c10f0f0d1ecd078f35f4
sha256: 2e873acd0b8ae423390298c825c6af41a6b1f501d8aa96dcc549887d93de49f1
sha512: 5d1f9bcebc2b05a7c8e7897833fc8786c017b8c1c7bdcdff97606784a47e27605e2fa4839b37ce1872b68b35b66f4badb5a48a42e70c7704440a3971abb36fe5
ssdeep: 12288:FkC3v0yb+FhCAOBORrtEMlO8iocldcCsLS27XLgXn0VEDffV1ojwnEeJRqcwGGaH:Fk609en6rCMI/oqdHsLS23i0iDHvJR7l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2E423C1F8C0E45BD25F1A3204ADDA3FF36A3AE895E6272F47DD8FB66D11C550A002A5
sha3_384: 3515da46bad3406716b150529445bf19fa94082c6a11dfdeec591b0fed3372f889b4de1853bf1c500531d767c86a17af
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-04-30 14:07:33

Version Info:

FileDescription: 快捷方式安装
InternalName: 快捷方式
LegalCopyright: Copyright (C) 2008 - 2009 KJfs Corporation.All rights reserved.
LegalTrademarks: 快捷方式
ProductName: 快捷方式
Translation: 0x0000 0x03a8

Malware.AI.2708552709 also known as:

LionicTrojan.Win32.StartPage.b!c
MicroWorld-eScanDeepScan:Generic.Startpage.2C9438A7
FireEyeDeepScan:Generic.Startpage.2C9438A7
CAT-QuickHealTrojanDropper.Startpage
McAfeeArtemis!7C0FD827CD7C
CylanceUnsafe
K7AntiVirusSpyware ( 004cfe271 )
K7GWSpyware ( 004cfe271 )
CyrenW32/Trojan.LPBV-3034
SymantecTrojan.Gen.2
ESET-NOD32NSIS/StartPage.BU
TrendMicro-HouseCallTROJ_GEN.R002H0CKS21
Paloaltogeneric.ml
ClamAVWin.Downloader.84425-1
KasperskyTrojan-Dropper.Win32.StartPage.aul
BitDefenderDeepScan:Generic.Startpage.2C9438A7
NANO-AntivirusTrojan.Nsis.StartPage.dmpdxk
AvastNSIS:StartPage-W [Trj]
TencentWin32.Trojan-dropper.Startpage.Ahfb
Ad-AwareDeepScan:Generic.Startpage.2C9438A7
ComodoApplication.Win32.MeinV.AK@57p4lw
BaiduNSIS.Trojan.StartPage.d
VIPRETrojan.Win32.Generic!BT
EmsisoftDeepScan:Generic.Startpage.2C9438A7 (B)
GDataDeepScan:Generic.Startpage.2C9438A7
AviraTR/StartPage.floec
Antiy-AVLTrojan/Generic.ASMalwNS.1AC
KingsoftWin32.Troj.Generic.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitDeepScan:Generic.Startpage.2C9438A7
ViRobotTrojan.Win32.Z.Startpage.682485
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.StartPage.C115322
VBA32TrojanDropper.Agent
ALYacDeepScan:Generic.Startpage.2C9438A7
MAXmalware (ai score=82)
MalwarebytesMalware.AI.2708552709
APEXMalicious
FortinetW32/StartPage.CHS!tr
AVGNSIS:StartPage-W [Trj]
Cybereasonmalicious.7cd7ce
PandaTrj/CI.A

How to remove Malware.AI.2708552709?

Malware.AI.2708552709 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment