Malware

How to remove “Malware.AI.498141268”?

Malware Removal

The Malware.AI.498141268 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.498141268 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Malware.AI.498141268?


File Info:

name: B37561919990CB02FE8E.mlw
path: /opt/CAPEv2/storage/binaries/17299f12f8d4f5f607c255a18abc044c1f6f5656e983684d8cefd1852254f183
crc32: 2218D5C0
md5: b37561919990cb02fe8e6e3eab0c1280
sha1: d591f9a492d1a1cdd2aec1c52bdd2039cc949a5d
sha256: 17299f12f8d4f5f607c255a18abc044c1f6f5656e983684d8cefd1852254f183
sha512: 267404d28288d9f3d019a7b0bab91702798eb267d0a3565aec9ef3d2089a3e69f3ae279de249b6f75d8e85eaf4a4eaf581c8f9deeb4493bbfa5aa0f01fd2be45
ssdeep: 24576:ZKuISjiW/Am88R0b3SdHvm1JUgaDH6nKz+THjpHHZ+uTt147dKh:ZKuqm2JUgPKz+TH9ZTz4pKh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B658D22F2415433D11316789D1FA7E9A615BF226F286C8777E43E4CAF3A7827834297
sha3_384: aca6d4cf98511b9a72e38d0c25a522f64cf8e9b7cf380a85289f5c5a629b23a0e20cba29f0d66f0e45b8d5d835ab5e28
ep_bytes: 558bec83c4f0b8b0fb5100e8bc66eeff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: l0wb1t
FileDescription: DEngine Trainer
FileVersion: 2.5.3.6
InternalName: DEngine Trainer
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: DEngine
ProductVersion: 1.2
Comments:
Trainer Page: http://kondorgames.de/forum/index.php?page=Board&boardID=42
Translation: 0x0407 0x04e4

Malware.AI.498141268 also known as:

FireEyeGeneric.mg.b37561919990cb02
McAfeeArtemis!B37561919990
CylanceUnsafe
ZillyaTool.CheatEngine.Win32.6187
SangforSuspicious.Win32.Attribute.HighConfidence
K7AntiVirusAdware ( 005693e61 )
K7GWAdware ( 005693e61 )
Cybereasonmalicious.492d1a
ESET-NOD32a variant of Win32/HackTool.CheatEngine.AB potentially unsafe
APEXMalicious
Paloaltogeneric.ml
AvastWin32:MdeClass
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Delf.abt (fs)
McAfee-GW-EditionArtemis
MaxSecureTrojan.Malware.300983.susgen
MicrosoftTrojan:Win32/Wacatac.A!ml
MalwarebytesMalware.AI.498141268
YandexTrojan.GenAsa!xXa7saN/qto
eGambitUnsafe.AI_Score_98%
FortinetRiskware/CheatEngine
WebrootW32.Adware.Gen
AVGWin32:MdeClass

How to remove Malware.AI.498141268?

Malware.AI.498141268 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment