Malware

Malware.AI.2800549431 removal

Malware Removal

The Malware.AI.2800549431 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2800549431 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete or modify volume shadow copies
  • Behavioural detection: Injection (inter-process)
  • Behavior consistent with a dropper attempting to download the next stage.
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2800549431?


File Info:

name: 6346CB9A08C181FE5209.mlw
path: /opt/CAPEv2/storage/binaries/f94e01e6c823d3b76ca0a7dba063736e593bbc08dfbf8fef8c0b6b3fbcaa630f
crc32: FEB157B6
md5: 6346cb9a08c181fe5209dc3e1cfb9f14
sha1: c72ee23518dd7d8296965aa116aa3af162e70321
sha256: f94e01e6c823d3b76ca0a7dba063736e593bbc08dfbf8fef8c0b6b3fbcaa630f
sha512: b7ac073b9cbda58a60a16123bb4cd782186325e19d6fd85344b0b768d472dac2985598fa47087eb74ce4a4ecfef45e08a3444c348e4f865aa5f87377e42c024b
ssdeep: 12288:HvwOYCHj2EN118Nh+RADq/duErBPRub44B:UCHH1UCjPRO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191D459AD9D98B071F3F495B5B573E3ABDF3E111B0B2ADE632C1001441F44284EA779AA
sha3_384: f515fae88d8bd4a82ea4b362f4b15342ad6a8b89f97a4dd62025a3c6c854783aefef151837a97174a76ecea2b477cf01
ep_bytes: 558bec81eca8010000535768ac734000
timestamp: 2016-06-07 08:47:47

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Updater AAM Launcher
FileVersion: 1,0,0,67
InternalName: aamlauncher.exe
LegalCopyright: Copyright 2009-10 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: aamlauncher.exe
ProductName: Adobe Updater AAM Launcher
ProductVersion: 1.0.0.67 (BuildVersion: 1.0; BuildDate: BUILDDATETIME)
BuildDate: Mon Feb 15 2010 02:31:20
BuildVersion: 1.0.0.67
Translation: 0x4009 0x04b0

Malware.AI.2800549431 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.G7
ALYacTrojan.Zbot.ITR
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
AlibabaBackdoor:Win32/Androm.0ded4d4b
K7GWTrojan ( 004f1c501 )
Cybereasonmalicious.a08c18
BaiduWin32.Trojan.Kryptik.azy
CyrenW32/Trojan.QR.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.EZKJ
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.jwkw
BitDefenderTrojan.Zbot.ITR
NANO-AntivirusTrojan.Win32.Androm.evdtot
MicroWorld-eScanTrojan.Zbot.ITR
TencentMalware.Win32.Gencirc.10b54da5
Ad-AwareTrojan.Zbot.ITR
SophosML/PE-A + Mal/Cerber-AK
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
DrWebTrojan.Encoder.4740
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRILOCK.NFH
McAfee-GW-EditionBehavesLike.Win32.PUPXFM.hm
FireEyeGeneric.mg.6346cb9a08c181fe
EmsisoftTrojan.Zbot.ITR (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Zbot.ITR
JiangminBackdoor.Androm.inv
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1105900
Antiy-AVLTrojan/Generic.ASMalwS.1905EF5
ArcabitTrojan.Zbot.ITR
SUPERAntiSpywareRansom.CryptoLocker/Variant
MicrosoftRansom:Win32/Teerac
TACHYONBackdoor/W32.Androm.598016
AhnLab-V3Trojan/Win32.ZBot.R182899
McAfeeRansomware-FNM!6346CB9A08C1
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesMalware.AI.2800549431
TrendMicro-HouseCallRansom_CRILOCK.NFH
RisingTrojan.Kryptik!1.AEE4 (CLASSIC)
YandexBackdoor.Androm!+knN4igyqhU
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Dridex.DD!tr
BitDefenderThetaGen:NN.ZexaF.34294.Ku0@aSV9HEii
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.2800549431?

Malware.AI.2800549431 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment