Malware

Malware.AI.2752221584 removal instruction

Malware Removal

The Malware.AI.2752221584 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2752221584 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • The following process appear to have been packed with Themida: brigma2.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to create or modify system certificates

Related domains:

wpad.local-net
www.public-trust.com

How to determine Malware.AI.2752221584?


File Info:

name: 832799D9FAD3B931B037.mlw
path: /opt/CAPEv2/storage/binaries/22f67b7dfc857133a756ea61ea21de0674edbc456b28461c0280598bdb050591
crc32: 21EF112F
md5: 832799d9fad3b931b0373504a4d54c5c
sha1: 276801b25422066efe29f3a81a492efd9ccc02a8
sha256: 22f67b7dfc857133a756ea61ea21de0674edbc456b28461c0280598bdb050591
sha512: 09b3fd8e9239cb839b947cb080c88c47ce54408ebda3252dd663d2de7a991cd4e9a4e61d1d143d08e72faea827be87df22777a7fb5f1e23c5d15cbe01fb0274d
ssdeep: 49152:73n19n+A3q2koWMeZ/zgqHcm7FLR6Fs4+ESTxNI8M2dmWa:719n+A3qLVHcmFoF95C9P+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140C533A237E1BB6ED8DB4A342DA18CF5CBF2E6717A95E07612C4EE8434EC3535C18152
sha3_384: a0a2c7974333fca6cd8848c35212ec88585433eac36cf3a0a3f8ae7b2bb1ded9e40b6e8fdaf34edcb5702c6712c5a9c3
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-07-25 00:55:47

Version Info:

FileDescription: bmdfbiednfigne4r5n23o54r3
FileVersion: 7.0.0.0
LegalCopyright:
Translation: 0x0409 0x0000

Malware.AI.2752221584 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Doina.846
FireEyeGeneric.mg.832799d9fad3b931
ALYacGen:Variant.Doina.846
CylanceUnsafe
SangforPUP.Win32.Ursu.129749
K7AntiVirusTrojan ( 005179b61 )
AlibabaTrojanDropper:Win32/Themida.177467db
K7GWTrojan ( 005179b61 )
CrowdStrikewin/malicious_confidence_80% (W)
SymantecTrojan.Dropper
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Doina.846
NANO-AntivirusTrojan.Win32.CoinMiner.eypuoq
AvastWin32:Malware-gen
TencentWin32.Trojan.Falsesign.Dxml
Ad-AwareGen:Variant.Doina.846
SophosMal/Generic-S
ComodoMalware@#3kasuvbyv6zi9
DrWebTrojan.MulDrop15.62138
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OKN21
EmsisoftGen:Variant.Doina.846 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.846
AviraHEUR/AGEN.1110758
Antiy-AVLTrojan/Generic.ASMalwS.3322E88
MicrosoftTrojan:Win32/Vigorf.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C2394166
McAfeeArtemis!832799D9FAD3
MAXmalware (ai score=99)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.2752221584
TrendMicro-HouseCallTROJ_GEN.R002C0OKN21
RisingTrojan.Generic@ML.93 (RDML:Sly7qT3tKALxiju9vZrkLw)
YandexTrojan.Miner!JVpZQUguarU
eGambitPE.Heur.InvalidSig
FortinetW32/Agent.CQ!tr
BitDefenderThetaGen:NN.ZexaF.34294.tA2aa8x8KQai
AVGWin32:Malware-gen
Cybereasonmalicious.9fad3b
PandaTrj/CI.A

How to remove Malware.AI.2752221584?

Malware.AI.2752221584 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment