Malware

Should I remove “Malware.AI.2961484404”?

Malware Removal

The Malware.AI.2961484404 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2961484404 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Malware.AI.2961484404?


File Info:

name: E1B95394B14AB2A7EA27.mlw
path: /opt/CAPEv2/storage/binaries/18df2d1f253f00b74559bdc982d3c7d149ec312c00c26ed12e9f3bf816e04bc3
crc32: 5C58CE27
md5: e1b95394b14ab2a7ea278bee9819c9c1
sha1: 39e31159515c13a405b271d6a3e58187cdc4ded0
sha256: 18df2d1f253f00b74559bdc982d3c7d149ec312c00c26ed12e9f3bf816e04bc3
sha512: ca98366f26e5dbeb898693bed32bfce83e576be261654dc8c3f24ef6dbdeb624e82436f3948d4a7651682439014327bb23f7ddbfea2375f0941d969bddaa56d5
ssdeep: 24576:2/XEXjJSNKKk3DgSB1jAhS1yUISfD5t9Gdog:2/oMkh18U1yiflGag
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE25F132B68CCC71C5E2143C5AD2B632253DBC241BA0C9871F947ADD6A7CD92F539E16
sha3_384: 955ae67d54f86567159d867f10a3fa7c14e9693653f47c64bd36f5fe3be4fbae0e1b747f3dcc037e0e13f528304b90be
ep_bytes: e815060000e978feffffe93f44000055
timestamp: 2022-01-24 07:31:24

Version Info:

0: [No Data]

Malware.AI.2961484404 also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.e1b95394b14ab2a7
McAfeeArtemis!4FEF5BFEC68D
ZillyaTrojan.Bingoml.Win32.8346
K7AntiVirusAdware ( 004b8c491 )
K7GWAdware ( 004b8c491 )
Cybereasonmalicious.4b14ab
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Generic@AI.99 (RDML:/U2Iakl24TLj8VYoymhWzg)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.10TFD8O
GoogleDetected
Acronissuspicious
MalwarebytesMalware.AI.2961484404
YandexTrojan.GenAsa!D1aLFjmKKvg
IkarusTrojan.Agent
FortinetW32/PossibleThreat
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.2961484404?

Malware.AI.2961484404 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment