Malware

Malware.AI.3459249514 removal tips

Malware Removal

The Malware.AI.3459249514 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3459249514 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3459249514?


File Info:

name: 413773389C4C3387D272.mlw
path: /opt/CAPEv2/storage/binaries/ede15facff761ba48703e50ac762d5e9f7ac04f4297902ede8f2a713f10c8388
crc32: 23553964
md5: 413773389c4c3387d27215bdc83d4f84
sha1: 9fe71016fac0785330b66b0266f19696fea3e8d0
sha256: ede15facff761ba48703e50ac762d5e9f7ac04f4297902ede8f2a713f10c8388
sha512: 6b2b69dedfabbadb7cb4ed93534ea94ace7c3a14962fdddbe5e1d1f64dc247133a573317592fd4211b133312d43c829a593f9757b00dfddd4856e6c514eeca81
ssdeep: 1536:bZwUSEf74FTRpHVLtn9rioyurjLAKqe3FspqXYX:N3SEUFFpTXj0Kqe1spqoX
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BA736C22B0A0C033D49219306D7CD6A29A6E7C335BB594C7BB94173B6FA42C19B753A7
sha3_384: 676ea5f9264acfd996d3826063e389d7fda4102ae16f0488ea602b2d36b38fc8ca635ea3373f1df53466618cbac18ef5
ep_bytes: e8e34b0000e995feffff660fefc05153
timestamp: 2018-11-30 22:02:09

Version Info:

OriginalFilename: otpfztq.exe
Translation: 0x0409 0x04b0

Malware.AI.3459249514 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Keylogger.Allinone.1
FireEyeGeneric.mg.413773389c4c3387
ALYacGen:Variant.Application.Keylogger.Allinone.1
CylanceUnsafe
K7AntiVirusTrojan ( 0050655e1 )
AlibabaRiskWare:Win32/BeyondKeyLogger.02bec670
K7GWTrojan ( 0050655e1 )
Cybereasonmalicious.89c4c3
CyrenW32/KeyLogger.AI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KeyLogger.AllInOneKeylogger.S
Paloaltogeneric.ml
CynetMalicious (score: 99)
Kasperskynot-a-virus:HEUR:Monitor.Win32.BeyondKeyLogger.heur
BitDefenderGen:Variant.Application.Keylogger.Allinone.1
AvastWin32:KeyloggerX-gen [Trj]
TencentWin32.Trojan.Application.Ozid
Ad-AwareGen:Variant.Application.Keylogger.Allinone.1
EmsisoftGen:Variant.Application.Keylogger.Allinone.1 (B)
ComodoTrojWare.Win32.KeyLogger.AllInOneKeylogger.PA@5xs4ue
McAfee-GW-EditionBehavesLike.Win32.Injector.lh
SophosGeneric PUA JP (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Application.Keylogger.Allinone.1
JiangminHeur:Trojan/PSW.Magania
AviraHEUR/AGEN.1113593
MAXmalware (ai score=72)
Antiy-AVLTrojan/Generic.ASMalwS.34DE366
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.Generic.C2482321
McAfeeGenericRXAA-FA!413773389C4C
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.3459249514
TrendMicro-HouseCallTROJ_GEN.R002H0CL121
RisingMalware.Heuristic!ET#95% (RDMK:cmRtazreUbNtITkU9tx6CDVfXbTN)
FortinetRiskware/AllInOneKeylogger
BitDefenderThetaGen:NN.ZexaF.34062.eu0@aKYwlZki
AVGWin32:KeyloggerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Malware.AI.3459249514?

Malware.AI.3459249514 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment