Malware

Malware.AI.686800942 malicious file

Malware Removal

The Malware.AI.686800942 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.686800942 virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Malware.AI.686800942?


File Info:

name: 22A940ED1E63B8F6D4D4.mlw
path: /opt/CAPEv2/storage/binaries/dafa75d4c9dc76dc0784adb50a754ae4638f01f223a4130bf54efa1a0cf4d38b
crc32: E7F1DBC9
md5: 22a940ed1e63b8f6d4d4029da8f00a27
sha1: 8b4bf3ead6e8f23fcf8728e4094cd8c9625a6fa8
sha256: dafa75d4c9dc76dc0784adb50a754ae4638f01f223a4130bf54efa1a0cf4d38b
sha512: 9635ec97da066a8ebca44d135b74e193428fd3482f5a1590959adb31ebfde752fce3452d39e979c77accc194ed54dd8bcf8db34086058fbc8d3abb8d2804cbf5
ssdeep: 3072:HDWuD4w3sWe/FbvDvvzZA4SfI+Ib3pbI9v0bWfsZ/c2ZQ8Iu:P4MsWe/FbBAXib1ZYu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188F3D489A3C8C714D5BE09341873C53572BFB452E001DBDF598E1DD91BEEB80EAD1AA2
sha3_384: 3751f3fe0fa9d7431f677ac262f3fa8feea4880cdd7a889ef06a7162bca37c980a4e146988a3f660cb7255e2bd95ad30
ep_bytes: ff25002040006100750074006f006600
timestamp: 2099-01-04 19:41:39

Version Info:

0: [No Data]

Malware.AI.686800942 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.21709
MicroWorld-eScanTrojan.GenericKDZ.80477
FireEyeGeneric.mg.22a940ed1e63b8f6
McAfeeGenericRXQA-AF!22A940ED1E63
MalwarebytesMalware.AI.686800942
K7AntiVirusSpyware ( 0057a2c81 )
K7GWSpyware ( 0057a2c81 )
Cybereasonmalicious.ad6e8f
CyrenW32/MSIL_Agent.CIU.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Spy.Agent.DFY
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.GenericKDZ.80477
Ad-AwareTrojan.GenericKDZ.80477
EmsisoftTrojan.GenericKDZ.80477 (B)
McAfee-GW-EditionBehavesLike.Win32.Backdoor.ch
IkarusTrojan.MSIL.Spy
GDataMSIL.Trojan.PSE.1KPC6YT
ArcabitTrojan.Generic.D13A5D
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.RedLine.C4784773
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKDZ.80477
MAXmalware (ai score=80)
APEXMalicious
RisingStealer.RedLine!1.DA64 (CLASSIC)
SentinelOneStatic AI – Malicious PE
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.686800942?

Malware.AI.686800942 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment