Malware

About “Malware.AI.4123972292” infection

Malware Removal

The Malware.AI.4123972292 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4123972292 virus can do?

  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.4123972292?


File Info:

name: F62619658B4D569C3D4B.mlw
path: /opt/CAPEv2/storage/binaries/ee7e772f4f72870933a1bbf812a870398802aa79bdf4699a34d6d7bb36d20847
crc32: 67AED720
md5: f62619658b4d569c3d4b0a03099e8c4f
sha1: b0d5a2e3a333bf750a537db5e2a6ff7e262a800f
sha256: ee7e772f4f72870933a1bbf812a870398802aa79bdf4699a34d6d7bb36d20847
sha512: e690fb3cb57d1c4cd58cab1604a0e3a17dbfa8d001b3fe38a6575b22f3445cca8b433eaf48a5bbe17e86a5771ca62dddc5af78a9a0ba49313d6a15fc365a1439
ssdeep: 6144:pQkKUzGT6ryDjlUY5QNEsSN4PxK77+/qBDZ3+C/ZjoErqRG8C1Ncys5:ukKErynynNEs44PiS2Z3+N5fCMZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A974E04393E9C044F5F65A31C9FA4AF49A72BC21FD30CEDB20107D6E38B6A509926767
sha3_384: 23bdc5e290ce7f3c2095a0c1f2efefd58e477d513d77a120f2ff421fb3b6a2cae3bd93bb8c46c3cf28c58d3ba5a0ad0c
ep_bytes: 60be002048008dbe00f0f7ff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: Homepage: http://softwarename.com
PrivateBuild:
ProductName: Software Name
FileVersion: 1.0.1.0
ProductVersion: 1.01
Translation: 0x0000 0x04b0

Malware.AI.4123972292 also known as:

BkavW32.Common.CB3D4576
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.535909
FireEyeGeneric.mg.f62619658b4d569c
CAT-QuickHealAdWare.ForceStartPage.A8
SkyhighBehavesLike.Win32.ObfuscatedPoly.fc
McAfeeGenericRXAA-AA!F62619658B4D
Cylanceunsafe
ZillyaAdware.ForceStartPage.Win32.10
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/ForceStartPage.44645fe7
BitDefenderThetaGen:NN.ZelphiF.36804.wmKfaGiAodkc
VirITAdware.Generic5.DOH
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DownloadGuru potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0PBH24
ClamAVWin.Trojan.Agent-359254
Kasperskynot-a-virus:AdWare.Win32.ForceStartPage.bi
BitDefenderGen:Variant.Zusy.535909
NANO-AntivirusTrojan.Win32.Searcher.tfyne
AvastWin32:PUP-gen [PUP]
TencentMalware.Win32.Gencirc.10b3594b
SophosStrictor (PUA)
F-SecureTrojan.TR/StartPage.879411
DrWebAdware.Searcher.1975
VIPREGen:Variant.Zusy.535909
TrendMicroTROJ_GEN.R002C0PBH24
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.535909 (B)
MAXmalware (ai score=99)
JiangminAdware.Agent.aizm
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/StartPage.879411
VaristW32/FierAds.A.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.ForceStartPage
KingsoftWin32.Troj.ForceStartPa.bi
XcitiumTrojWare.Win32.Agent.KDV@4ok15r
ArcabitTrojan.Zusy.D82D65
ViRobotAdware.Forcestartpage.364032.AXX
ZoneAlarmnot-a-virus:AdWare.Win32.ForceStartPage.bi
GDataGen:Variant.Zusy.535909
CynetMalicious (score: 99)
AhnLab-V3Adware/Win32.Strictor.R26857
VBA32BScope.Adware.ForceStartPage
ALYacGen:Variant.Zusy.535909
MalwarebytesMalware.AI.4123972292
PandaTrj/CI.A
RisingTrojan.Win32.Generic.12D07E7B (C64:YzY0Ogbt/z4f7Ghd)
YandexTrojan.GenAsa!v6IBKgi1Ac8
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.6207715.susgen
FortinetRiskware/DownloadGuru
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS
alibabacloudAdWare:Win/ForceStartPage.bi

How to remove Malware.AI.4123972292?

Malware.AI.4123972292 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment