Malware

Malware.AI.665498609 information

Malware Removal

The Malware.AI.665498609 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.665498609 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Attempts to modify proxy settings

How to determine Malware.AI.665498609?


File Info:

name: 4CBAE3A1D5C7D1B9F5E9.mlw
path: /opt/CAPEv2/storage/binaries/22c508ea2043142dbccd2f9c6eb358c73be7e110269809ca6cb4ccfb196e3052
crc32: 1909A272
md5: 4cbae3a1d5c7d1b9f5e94c3662b6f3d7
sha1: 77db6c42ceaefc9bd222cfd1a90505e1b6536ef0
sha256: 22c508ea2043142dbccd2f9c6eb358c73be7e110269809ca6cb4ccfb196e3052
sha512: f228cc608687a91afe91296fcf562ec74120f0e7911c066c82ab40b8fd04cd69270dee593df125f1921550dcf1043c08d58ffcfe122ddcd3fd843cfd5eb8ee8a
ssdeep: 24576:WdLQ9el6mc+lZ62gEHY17I6RxHX5BuzKl:+sG6H6iozi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2658D72A65BACE9C3C06031E8509A2B7D39ADBD2B3855F3679C3C7E75750DA8138306
sha3_384: 37d73068ea732a59e29ecd4841715d06c24b92699c26dadaab8ff79d4844b56669a8aa63776bf5ec846548e99fa8ec0b
ep_bytes: e8025e0000e989feffff8bff558bec51
timestamp: 2020-07-17 10:53:50

Version Info:

FileDescription:
FileVersion: 1.1.33.02
InternalName:
LegalCopyright:
OriginalFilename:
ProductName:
ProductVersion: 1.1.33.02
Translation: 0x0409 0x04b0

Malware.AI.665498609 also known as:

LionicTrojan.Win32.Taskun.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38213991
FireEyeGeneric.mg.4cbae3a1d5c7d1b9
ALYacTrojan.GenericKD.38213991
CylanceUnsafe
K7AntiVirusTrojan ( 0054b4d81 )
AlibabaTrojanDownloader:Win32/Taskun.6847f2e0
K7GWTrojan ( 0054b4d81 )
CyrenW32/Trojan.DJGM-7518
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/RiskWare.GameHack.CT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Taskun.aea
BitDefenderTrojan.GenericKD.38213991
AvastFileRepMalware
TencentWin32.Trojan-downloader.Taskun.Pgni
Ad-AwareTrojan.GenericKD.38213991
EmsisoftTrojan.GenericKD.38213991 (B)
ZillyaTrojan.APosT.Win32.1659
TrendMicroTROJ_GEN.R002C0PLA21
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
GDataWin32.Trojan.Agent.6UHF0Z
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
McAfeeArtemis!4CBAE3A1D5C7
MAXmalware (ai score=82)
MalwarebytesMalware.AI.665498609
TrendMicro-HouseCallTROJ_GEN.R002C0PLA21
RisingTrojan.Generic@ML.100 (RDML:3REcSAfJRZp/5ZGe8Trj0g)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/GameHack
AVGFileRepMalware
PandaTrj/CI.A

How to remove Malware.AI.665498609?

Malware.AI.665498609 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment