Malware

How to remove “Malware.AI.2991073059”?

Malware Removal

The Malware.AI.2991073059 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2991073059 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Malware.AI.2991073059?


File Info:

name: 95FE2165FE94496F5C34.mlw
path: /opt/CAPEv2/storage/binaries/4cb625f928fa37b24294cd7d0c74ab71c6c9b5e6eb9be529e922ab1ffed34dbc
crc32: 855748C2
md5: 95fe2165fe94496f5c3404ad3f7ff9a4
sha1: f25830ce6c9502e81d4bdeea3f6de336682eb538
sha256: 4cb625f928fa37b24294cd7d0c74ab71c6c9b5e6eb9be529e922ab1ffed34dbc
sha512: b4914120271bbf5f7acf2abd6eefbadb3ccd07fd408c69c7d27abb4248abaf5ba77028f3c33220f70995a97e14316084cef1790a3164e83f4d808e5c852b45d7
ssdeep: 12288:4bcYbBWMsm6LZ1XITj2KixRiUeLjXVwPmNU34ZPGtZvUXjgYAC:4bcYNWc6Lv+XoeZ3ZPmZvUXMXC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172D41212B365CD5BE12A0EB145B6D9BEADB0BD609E014B0773E07A5F3C76380B40F699
sha3_384: e37e82a86ac1d931b35a38322633854fe5534b5e5bcacd54d9520614eefd4cf6cb36cbe8e34b0902c0cbd3b17f265255
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

Comments: Besm102
CompanyName: Fejlslutni44
FileDescription: Itshjernerystel
FileVersion: 30.9.11
LegalCopyright: Unduene138
LegalTrademarks: analysabi
ProductName: elektri
Translation: 0x0409 0x04b0

Malware.AI.2991073059 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Nemesis.8217
FireEyeGen:Variant.Nemesis.8217
ALYacGen:Variant.Nemesis.8217
CylanceUnsafe
K7AntiVirusTrojan ( 0059035d1 )
AlibabaTrojan:Win32/Shelsy.4434fd81
K7GWTrojan ( 0059035d1 )
ESET-NOD32NSIS/Injector.ASH
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Shelsy.gen
BitDefenderGen:Variant.Nemesis.8217
AvastNSIS:MalwareX-gen [Trj]
TencentWin32.Trojan.Falsesign.Hwda
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Nemesis.8217 (B)
GDataGen:Variant.Nemesis.8217
WebrootW32.Trojan.Dropper
AviraTR/Injector.arypn
ArcabitTrojan.Nemesis.D2019
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!95FE2165FE94
MAXmalware (ai score=84)
MalwarebytesMalware.AI.2991073059
TrendMicro-HouseCallTROJ_GEN.R002H0DFE22
IkarusTrojan.NSIS.Agent
AVGNSIS:MalwareX-gen [Trj]

How to remove Malware.AI.2991073059?

Malware.AI.2991073059 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment