Malware

About “Malware.AI.2717774152” infection

Malware Removal

The Malware.AI.2717774152 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2717774152 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Malware.AI.2717774152?


File Info:

name: CC66A739064FF8D7268A.mlw
path: /opt/CAPEv2/storage/binaries/73652f3a576856926fe0805da9e3afcb7d954fcda47411df7eec7fcb68738168
crc32: 26FECD8F
md5: cc66a739064ff8d7268a81ebdb9f2886
sha1: 2de6e80873147ebd2696049c003f0fa2c6ff4682
sha256: 73652f3a576856926fe0805da9e3afcb7d954fcda47411df7eec7fcb68738168
sha512: 0275d0dc985cdbfd5f08e8f7126ba37b878633004a7bcb90c7d47b4e52f28b58e4b8bf6ed00ea0528213ef99f9480381881e4a278c06f15df9250a71ad41b893
ssdeep: 6144:g1mP62UK5zfunQgGysTJ5DOgwoq2bBcQfhqDT31:gW+GHDd/fhqDTl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A294CF1362948C07FCB56EF8C57272D08924B8705E22871B3AD59B5DF6B3AD0EA7D312
sha3_384: 454d5297a99950603c7b0ad9b1413758d52b9b524e50b436e8c81d3d44c327a89f4f1de081dde88f239a316d57cbaaeb
ep_bytes: 558bec81ecd4030000c785acfeffff00
timestamp: 2012-05-08 20:45:01

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows TaskManager
FileVersion: 5.00.2137.1
InternalName: taskmgr
LegalCopyright: Copyright (C) Microsoft Corp. 1991-1999
OriginalFilename: taskmgr.exe
ProductName: Microsoft(R) Windows (R) 2000 Operating System
ProductVersion: 5.00.2137.1
Translation: 0x0409 0x04b0

Malware.AI.2717774152 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.cc66a739064ff8d7
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeePWS-Zbot.gen.bex
CylanceUnsafe
ZillyaTrojan.Carberp.Win32.2065
SangforTrojan.Win32.Kazy.512644
K7AntiVirusSpyware ( 0040ae601 )
AlibabaTrojan:Win32/Ramdo.dfce36a8
K7GWSpyware ( 0040ae601 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34212.Au1@aG9m8Pfi
VirITTrojan.Win32.Generic.CEWN
CyrenW32/Zbot.DQ.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.AFGT
BaiduWin32.Adware.Kryptik.b
TrendMicro-HouseCallTROJ_AGENT_037974.TOMB
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-358247
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.733987
NANO-AntivirusTrojan.Win32.Carberp.cslymv
MicroWorld-eScanGen:Variant.Razy.733987
APEXMalicious
TencentMalware.Win32.Gencirc.10b5e21c
Ad-AwareGen:Variant.Razy.733987
EmsisoftGen:Variant.Razy.733987 (B)
ComodoTrojWare.Win32.Kryptik.ASR@4oc4x0
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebTrojan.Carberp.340
VIPRETrojan-PWS.Win32.Zbot.aql (v)
TrendMicroTROJ_AGENT_037974.TOMB
McAfee-GW-EditionPWS-Zbot.gen.bex
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.733987
JiangminTrojan/Generic.ackhs
WebrootW32.Rogue.Gen
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Carberp
KingsoftHeur.SSC.2774859.1216.(kcloud)
ArcabitTrojan.Razy.DB3323
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ramdo.A
AhnLab-V3Trojan/Win32.Zbot.R26291
Acronissuspicious
VBA32Trojan-Injector.FakeTaskmgr.14505
ALYacGen:Variant.Razy.733987
MalwarebytesMalware.AI.2717774152
AvastWin32:Karagany
RisingDownloader.Carberp!8.2EB (CLOUD)
YandexTrojan.Agent!mbH7I2/U9LM
IkarusTrojan-Downloader.Win32.Carberp
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/ZBOT.HL!tr
AVGWin32:Karagany
Cybereasonmalicious.9064ff
PandaBck/Qbot.AO

How to remove Malware.AI.2717774152?

Malware.AI.2717774152 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment