Malware

Malware.AI.2752691838 removal guide

Malware Removal

The Malware.AI.2752691838 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2752691838 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Malware.AI.2752691838?


File Info:

name: 191D98E4291A4DA424F4.mlw
path: /opt/CAPEv2/storage/binaries/462c4ab689e88149cd3543ac37854e4af61c9044dd69fce84d03a4836428987f
crc32: C7E58C03
md5: 191d98e4291a4da424f4cf06dd06708b
sha1: 3a681633592bcb7d584914c834b3aebcecd3ceb5
sha256: 462c4ab689e88149cd3543ac37854e4af61c9044dd69fce84d03a4836428987f
sha512: 44294ffe29ff825463a1a73dc7b8811fa4101119023c5dfad4a36e3817fb0cea375ff4a80e7f9e22b8f529251969e019a91208c021b543cd1b21718fad4256dd
ssdeep: 3072:fb1EFzjfkDdofYRxYv0sSpMU4HBipcfAc6hMEEjelnSc8iq4yVP8peRu2kay+sHU:kpSh4Hgp4ABZyiq46Upf5Yc1jh4HwC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F340A97B7F0F3B5E20681F152942AF512F9553118A46C0BC3C21B39B7B0A97AA74F1B
sha3_384: 3def6ac4d6bf9f2c89c264be51be2d544d2a8547c605cd43194b630a27317ce8814cc4d44fecf6644dab37655121f068
ep_bytes: 68f4384000e8f0ffffff000000000000
timestamp: 2010-02-19 11:13:54

Version Info:

Translation: 0x0407 0x04b0
Comments: CMdjhkgbfzahueoigaFASIEUhaFAJHVFauhaihfouai787470379hluahgofuiazhi
LegalCopyright: uhauzodhrlfaopehljajdvnhhaoiuADJuepauiFADIEEINVaio9847t98z437hlkahpd
LegalTrademarks: ewaopuhezoagbfäAJFAUEAFUAHfiuaouzehauAIIAIPOPEKIDJjiaofjoif438hdps
ProductName: OEIEJJAJajieu748z93679092267piuhfa00oafhoaiuhdfzagzaiu6w7oiuapiuz
FileVersion: 1.02.0192
ProductVersion: 1.02.0192
InternalName: grutzka
OriginalFilename: grutzka.exe

Malware.AI.2752691838 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.68
MicroWorld-eScanGen:Variant.Johnnie.3479
FireEyeGeneric.mg.191d98e4291a4da4
CAT-QuickHealVirTool.Vbinder.Gen
McAfeeGenericR-DEU!191D98E4291A
CylanceUnsafe
VIPREVirTool.Win32.Vbinder.gen.g (v)
K7GWTrojan ( 004d05801 )
K7AntiVirusTrojan ( 004d05801 )
BitDefenderThetaGen:NN.ZevbaF.34294.pm1@amhjV0z
CyrenW32/VBCrypt.A!Generic
ESET-NOD32a variant of Win32/Injector.BRK
TrendMicro-HouseCallBKDR_BIFROSE.DSY
ClamAVWin.Trojan.Bifrose-6823881-0
BitDefenderGen:Variant.Johnnie.3479
NANO-AntivirusTrojan.Win32.Bifrose.byozb
SUPERAntiSpywareTrojan.Agent/Gen-Falprod[Cont]
AvastWin32:Bifrose-ENO [Trj]
TencentMalware.Win32.Gencirc.114b32f0
Ad-AwareGen:Variant.Johnnie.3479
EmsisoftGen:Variant.Johnnie.3479 (B)
ComodoBackdoor.Win32.Bifrose.~CGMG@1rwzgt
ZillyaWorm.WBNA.Win32.472318
TrendMicroBKDR_BIFROSE.DSY
SophosMal/Generic-R + Mal/VBCheMan-C
IkarusBackdoor.Win32.Bifrose
GDataGen:Variant.Johnnie.3479
JiangminBackdoor/Bifrose.aqia
WebrootVir.Tool.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.5
KingsoftWin32.Hack.Bifrose.(kcloud)
ViRobotBackdoor.Win32.Bifrose.626510
MicrosoftPWS:Win32/Zbot.GG!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bifrose.R6046
VBA32SIM.Trojan.VBO.02751
ALYacGen:Variant.Johnnie.3479
MAXmalware (ai score=89)
MalwarebytesMalware.AI.2752691838
APEXMalicious
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!4jWdcVkkjYc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_56%
FortinetW32/VBInjector.W!tr
AVGWin32:Bifrose-ENO [Trj]
Cybereasonmalicious.4291a4
PandaGeneric Malware
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Malware.AI.2752691838?

Malware.AI.2752691838 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment