Malware

How to remove “Malware.AI.2250821”?

Malware Removal

The Malware.AI.2250821 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2250821 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering

How to determine Malware.AI.2250821?


File Info:

name: 01ADA945966AF4259EC5.mlw
path: /opt/CAPEv2/storage/binaries/9467a169377bf5766f443246dbff386ef357bc12fecec42e99b262cda8df8eb1
crc32: 4B29F8CC
md5: 01ada945966af4259ec55175cee80ebb
sha1: 33973385f14437628c5f14a3d95125bb51823e1d
sha256: 9467a169377bf5766f443246dbff386ef357bc12fecec42e99b262cda8df8eb1
sha512: 2e8ad6b69b822e40134185730a977e3f586c9c5b3c7abb96345ef845b5d25b4022a66eaee83c6c8c08a067afae0a9a85c8f05590bb914737ffc5db9daab7a9dd
ssdeep: 6144:2VoZcPWLTkg9KHr4fnJWSdJoGTK+RQkLZ:VZcPYKr4fnJPJoN+RnLZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160349E4376984B11E96849B5C0FB683503E2AECB1733E5953F4C63CD2D137A38DA9B89
sha3_384: 5d1a711158519bb476f8905afa12d5ed69ac830c67957c2448078b80a69a1dd93031d880fbc4075d1c2355715d08e2fa
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-03-08 17:51:07

Version Info:

Translation: 0x0000 0x04b0
CompanyName: 游民星空
FileDescription: 启动程序
FileVersion: 1.2
InternalName: Shell.exe
LegalCopyright: 版权所有 (C) 游民星空 2012
OriginalFilename: Shell.exe
ProductName: 启动程序
ProductVersion: 1.2
Assembly Version: 1.0.0.0

Malware.AI.2250821 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.01ada945966af425
SkyhighGenericRXEQ-YL!01ADA945966A
McAfeeGenericRXEQ-YL!01ADA945966A
MalwarebytesMalware.AI.2250821
SangforTrojan.Win32.Agent.V7yf
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ClamAVWin.Malware.Wapomi-7012356-0
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
SophosGeneric Reputation PUA (PUA)
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
GoogleDetected
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06CT23
IkarusTrojan.Msil
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
DeepInstinctMALICIOUS

How to remove Malware.AI.2250821?

Malware.AI.2250821 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment