Malware

Malware.AI.2791799846 removal instruction

Malware Removal

The Malware.AI.2791799846 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2791799846 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.2791799846?


File Info:

name: 24741479B3DF2AEDCDA7.mlw
path: /opt/CAPEv2/storage/binaries/1c8477da535ab89af20180a7854220de6ef2c8b7646343dca0d461f5ad6420c1
crc32: 56FA4E10
md5: 24741479b3df2aedcda7d766f009aec1
sha1: b27275d4156b4edcb8e0ed5121fb1d6c7e190f5c
sha256: 1c8477da535ab89af20180a7854220de6ef2c8b7646343dca0d461f5ad6420c1
sha512: 3fa20993390ddffaafb7511a8be9d48c6e4dab3d106e5c85834538e4bb574bed40720c1df19afb84bb75f4424c1ebc167ccfa52bd01c37d6c837c22f1ed3bece
ssdeep: 6144:+gSgfgSg+gSgfgSgqgSgfgSg+gSgfgSg:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F857D036B443E73CB67053B0CB74636D5B2D3408728C9C3AFA468696B567E17E7A349
sha3_384: a97595fd0fd44f2b8faf97252466e1289c4ab260964933d1017d209e3f73117cb397b6d2bd42839129e05050ce584cfa
ep_bytes: 682400000068000000006864644000e8
timestamp: 2016-03-01 22:44:44

Version Info:

0: [No Data]

Malware.AI.2791799846 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agentb.trWi
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.22576
MicroWorld-eScanTrojan.Agent.EYLR
FireEyeGeneric.mg.24741479b3df2aed
CAT-QuickHealTrojan.WacatacPMF.S23662359
ALYacTrojan.Agent.EYLR
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2492729
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/PolyPatch.2b61942b
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.9b3df2
BitDefenderThetaGen:NN.ZexaF.34160.WnZ@aKWVmzli
CyrenW32/Agent.DRI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.ADMM
TrendMicro-HouseCallTROJ_GEN.R002C0PLR21
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.Agent.EYLR
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.wb
Ad-AwareTrojan.Agent.EYLR
TACHYONTrojan/W32.Agent.1835008.CN
EmsisoftTrojan.Agent.EYLR (B)
TrendMicroTROJ_GEN.R002C0PLR21
McAfee-GW-EditionPolyPatch-UPX
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.1YNUJ22
JiangminTrojan.Agent.dlnq
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.204A4E5
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Agent.EYLR
ViRobotTrojan.Win32.Z.Agent.1835008.AKU
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.UPX.C4686120
Acronissuspicious
McAfeePolyPatch-UPX
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.2791799846
APEXMalicious
RisingTrojan.Agent!1.D9AC (CLOUD)
YandexTrojan.Agent!vTCD6dhRwms
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.ADMM!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.2791799846?

Malware.AI.2791799846 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment