Malware

Malware.AI.4015882530 removal instruction

Malware Removal

The Malware.AI.4015882530 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4015882530 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Writes a potential ransom message to disk
  • Created a process from a suspicious location
  • A script process created a new process

How to determine Malware.AI.4015882530?


File Info:

name: 126161CF937742E964AE.mlw
path: /opt/CAPEv2/storage/binaries/cbd3e7540afcfc3e07c2525c5f5f090eee8d7a2b24f61974fe0d8b99924bb10a
crc32: 313B7071
md5: 126161cf937742e964ae3003bf77371b
sha1: 45405824af91bd22eb34c7fded466aa6e2d6ea32
sha256: cbd3e7540afcfc3e07c2525c5f5f090eee8d7a2b24f61974fe0d8b99924bb10a
sha512: 325c855a9b12a87807566b72ff1e2b52ac0665efad89c147d8b49ad69d1c515f50bf1b24a908352de75dae6bd27890e4b36ee00cf4e5d7ac6edd178889d18b2b
ssdeep: 12288:UsOW6Q4OWz9hzhFzyH+XHzBeU08FE23XHd74FE2cd1a4Pyu5UJ:mW6VXRhtFzyeXzbFVXSFUZXi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4F40203F6C684B3E87205354A29A756697DB6301F25CE6FF3D84C6A9D701A0A331FA7
sha3_384: efd86fa7c9617088282bf5026c92552625d00608c68f53906ef9e232bf81b61100fef8a85ea4d78bcac5522d6d2f64b1
ep_bytes: e89e040000e98efeffff3b0dc8a14300
timestamp: 2018-06-24 15:04:40

Version Info:

0: [No Data]

Malware.AI.4015882530 also known as:

LionicTrojan.Win32.Joker.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38953082
CylanceUnsafe
K7AntiVirusTrojan ( 005897a01 )
BitDefenderTrojan.GenericKD.38953082
K7GWTrojan ( 005897a01 )
ArcabitTrojan.Generic.D252607A
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Agent.a
AlibabaTrojan:BAT/RenameFiles.53097197
MicroWorld-eScanTrojan.GenericKD.38953082
Ad-AwareTrojan.GenericKD.38953082
EmsisoftTrojan.GenericKD.38953082 (B)
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.126161cf937742e9
SophosMal/Generic-S
WebrootW32.Malware.Gen
AviraTR/Redcap.gpuce
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Kryptik!MSR
ZoneAlarmHoax.BAT.FakeRansom.c
GDataWin32.Trojan.Agent.OHSWER
AhnLab-V3Trojan/Win.Trojan-gen.C4949318
McAfeeRDN/Generic.dx
MAXmalware (ai score=81)
MalwarebytesMalware.AI.4015882530
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
TencentBat.Trojan.Generic.Dvzl
FortinetW32/NDAoF!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.4015882530?

Malware.AI.4015882530 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment