Malware

About “Malware.AI.4092962492” infection

Malware Removal

The Malware.AI.4092962492 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4092962492 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Enumerates physical drives
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.4092962492?


File Info:

name: BE2FD5A51D9E7F00C33F.mlw
path: /opt/CAPEv2/storage/binaries/9807d116e2f0f82907ba7a1f324799344a000724f95b7b99b6ac004930066bf5
crc32: CE963386
md5: be2fd5a51d9e7f00c33f77e97572735c
sha1: 33759dedd1bd71c26dcd1da7d3a94e5e7795c63e
sha256: 9807d116e2f0f82907ba7a1f324799344a000724f95b7b99b6ac004930066bf5
sha512: 78558c6efcf72e036c20c888b6e1ab119cdf97745b347c9300e7987956b808c05975766ed0ffcf834592b2a924190b5824435219fce8a404f29bca1138610dd9
ssdeep: 768:77IP1/QsgIG4ohrjropxrB4mlhDN08Igg8apQrw2xUoC/D8HUarmxCWxpOeqL0V5:77s1IZIg9PGH44IB4MRfq+dJEXGIlYq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FFF39D2E21EBF95AE0B2AB3A01B1F1B1BE75FDB15327474795830F2A500C4F5497293A
sha3_384: 986f75184d6b793d5db33f34e3282c16f95b0ac1681990e8c89eb727003a08ed43aef0ecc8dbcbf586d6855a32a49185
ep_bytes: 8b3d6869420001c18b15086b4200a158
timestamp: 2009-12-04 17:08:43

Version Info:

Comments:
CompanyName: Sun Microsystems, Inc.
FileDescription: qMicro setup W
FileVersion: 2.0.0.71
InternalName: mYgoingO.exe
LegalCopyright: Copyright © 2009 wSun Microsystems All rights reserved.CM
LegalTrademarks:
OriginalFilename: mYgoingO.exe
ProductName: K
ProductVersion: 2.0.0.71
Translation: 0x0409 0x04e4

Malware.AI.4092962492 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CodecPack.lngW
tehtrisGeneric.Malware
DrWebTrojan.DownLoader4.6385
MicroWorld-eScanGen:Variant.Zbot.10
ClamAVWin.Downloader.109702-1
FireEyeGeneric.mg.be2fd5a51d9e7f00
CAT-QuickHealTrojan.Renos.LN
SkyhighDownloader-CEW.au
ALYacGen:Variant.Zbot.10
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.107552
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/CodecPack.760dd878
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36744.jy0@amQYaTbi
VirITTrojan.Win32.Generic.AZFA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.FakeAlert.BBT
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.CodecPack.axuw
BitDefenderGen:Variant.Zbot.10
NANO-AntivirusTrojan.Win32.CodecPack.cpxsa
AvastWin32:Renos-AYD [Trj]
TencentMalware.Win32.Gencirc.10b1283e
EmsisoftGen:Variant.Zbot.10 (B)
F-SecureTrojan.TR/Dldr.Reno.PT.141
VIPREGen:Variant.Zbot.10
TrendMicroTROJ_RENOS.SMCE
Trapminesuspicious.low.ml.score
SophosMal/FakeAV-IZ
IkarusTrojan-Downloader.Win32.FakeAlert
GDataGen:Variant.Zbot.10
JiangminTrojanDownloader.CodecPack.diw
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Dldr.Reno.PT.141
Antiy-AVLTrojan[Downloader]/Win32.CodecPack
KingsoftWin32.HeurC.KVMH008.a
XcitiumTrojWare.Win32.Kryptik.ZZ@3tur67
ArcabitTrojan.Zbot.10
ViRobotTrojan.Win32.CodecPack.160768
ZoneAlarmTrojan-Downloader.Win32.CodecPack.axuw
MicrosoftTrojanDownloader:Win32/Renos.PT
VaristW32/Downloader.CO.gen!Eldorado
AhnLab-V3Win-Trojan/Fakeav.160768.HV
Acronissuspicious
McAfeeDownloader-CEW.au
MAXmalware (ai score=100)
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.4092962492
PandaAdware/ResonatorA
TrendMicro-HouseCallTROJ_RENOS.SMCE
RisingDownloader.CodecPack!8.2EC1 (TFE:1:otVWM4opjUM)
YandexTrojan.DL.CodecPack!U8Zc2aqHLPk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2416064.susgen
FortinetW32/Krypt.QKV!tr
AVGWin32:Renos-AYD [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.4092962492?

Malware.AI.4092962492 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment