Malware

Win64/Exploit.CVE-2021-41379.A removal guide

Malware Removal

The Win64/Exploit.CVE-2021-41379.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Exploit.CVE-2021-41379.A virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

Related domains:

wpad.local-net

How to determine Win64/Exploit.CVE-2021-41379.A?


File Info:

name: 2DA3E71C2FFCED06B9D6.mlw
path: /opt/CAPEv2/storage/binaries/2d8471cf29e205c9df9d1235e3acfff3d99810bdc262667fdf7629eb92028ede
crc32: FA2BE874
md5: 2da3e71c2ffced06b9d662ccf12411c5
sha1: eb2305d012faa3301b551ff781ccd70426107e12
sha256: 2d8471cf29e205c9df9d1235e3acfff3d99810bdc262667fdf7629eb92028ede
sha512: 94c3e5e65ee40697c57ce3b733777491d60f47674350ef8ba1255fc18494cfcf42e82a2eed6b18d828a51fecb71ea0b9e7dd81cb98d301c720dbd8ad0d4f9770
ssdeep: 49152:EUgbYXwB3FHjD5JPz1MbEUl8VlvfxA7vW/LL4Ni:AYk5JPpYEkMAzWz8i
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T15075DF1176D6C53BC46701701E2ADB7AA239BD700B32C5EBA3D85D2F2E716C05A72F92
sha3_384: af07bfee99d9070d1e5db391741e0482811324c9aea34486a011923b4ee35ab4b44f319000f8372b012456de1409a305
ep_bytes: 4883ec28e8fb0300004883c428e972fe
timestamp: 2021-11-23 16:29:43

Version Info:

0: [No Data]

Win64/Exploit.CVE-2021-41379.A also known as:

LionicTrojan.OLE2.Agent.3!c
MicroWorld-eScanTrojan.GenericKD.38106270
McAfeeArtemis!2DA3E71C2FFC
CylanceUnsafe
AlibabaExploit:Win32/Generic.5c5bb800
K7AntiVirusTrojan ( 0058ae0c1 )
CyrenW64/MSIL_Agent.CKS.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/Exploit.CVE-2021-41379.A
KasperskyHEUR:Exploit.OLE2.Agent.gen
BitDefenderTrojan.GenericKD.38106270
AvastOther:Malware-gen [Trj]
Ad-AwareTrojan.GenericKD.38106270
SophosExp/2141379-A
ComodoTrojWare.Win32.Agent.tmgtp@0
DrWebExploit.CVE-2021-41379.3
TrendMicroTrojan.Win64.CVE202141379.YXBKYZ
McAfee-GW-EditionBehavesLike.Win64.Dropper.tc
FireEyeTrojan.GenericKD.38106270
EmsisoftTrojan.GenericKD.38106270 (B)
IkarusExploit.CVE-2021-41379
GDataWin32.Exploit.CVE_2021_41379.C
WebrootW32.Malware.Gen
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win64.Wacatac.sa
ArcabitTrojan.Generic.D245749E
MicrosoftTrojan:Win32/Infistov
AhnLab-V3Trojan/Win.Infistov.R453305
VBA32Exploit.OLE2
ALYacExploit.CVE-2021-41379
MAXmalware (ai score=88)
TrendMicro-HouseCallTrojan.Win64.CVE202141379.YXBKYZ
RisingExploit.CVE-2021-41379!1.DABC (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CVE_2021_41379.A!exploit
AVGOther:Malware-gen [Trj]
PandaTrj/CI.A

How to remove Win64/Exploit.CVE-2021-41379.A?

Win64/Exploit.CVE-2021-41379.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment