Malware

Malware.AI.4131324803 removal

Malware Removal

The Malware.AI.4131324803 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4131324803 virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Malware.AI.4131324803?


File Info:

name: 225010EE2958082EF8B3.mlw
path: /opt/CAPEv2/storage/binaries/42fcf4a38b541a5480505139512a7b6f5a0343b6cc765d24ab9a52b1e5bae9cc
crc32: A81D2414
md5: 225010ee2958082ef8b35e5f43c5d0fc
sha1: f3363c0c337e0e73cc0ee6b482b44047ed51c991
sha256: 42fcf4a38b541a5480505139512a7b6f5a0343b6cc765d24ab9a52b1e5bae9cc
sha512: a73ffadefa640ef56e6524a19fdc87fb9ad141e9958f9552b732069e1b2b55837ba3f88b692bec0cde739404d090edf61b99b9e0fa248b29b055be7b0e8fedc2
ssdeep: 12288:dqzWUsKOQ7IdUMZRHo0dZn6qtB+pqnzBEjDkXdp4SAkpMbcBC7DAXbeEf3c:5UsIaUcxeqtB+p3w348BaD+bees
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104F4238DC2CF0CAACC005AB7526FEE52E80AD51EE9D24F9F178D9D150D232195CB4B7A
sha3_384: a421f26dbdaf6a031a772eb4a738c8947de08576f5c9d3721c077b7ba1dea6d1823a674e8e2cbacfd20229e98fdc56d8
ep_bytes: 687d0b592d68af082c46c7442404d3d5
timestamp: 2012-09-21 07:00:35

Version Info:

FileVersion: 1.0.0.1
FileDescription: 刷雷者
ProductName: 刷雷者
ProductVersion: 1.0.0.1
CompanyName: www.wg148.com
LegalCopyright: 技术:YY3820山炮版权所有
Comments: 1,0,0,1
Translation: 0x0804 0x04b0

Malware.AI.4131324803 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MalwarebytesMalware.AI.4131324803
K7AntiVirusAdware ( 004b942f1 )
K7GWAdware ( 004b942f1 )
Cybereasonmalicious.c337e0
CyrenW32/S-ec8de4dc!Eldorado
SymantecPacked.Vmpbad!gen1
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.AAA
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
ZillyaTrojan.Packed.Win32.74212
TrendMicroTROJ_GEN.R014C0CIF23
McAfee-GW-EditionBehavesLike.Win32.VirRansom.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.225010ee2958082e
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftVirTool:Win32/Obfuscator.XZ
GoogleDetected
McAfeeGeneric-FAAF!225010EE2958
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R014C0CIF23
RisingHackTool.Obfuscator!8.236 (TFE:2:xLTOxWybsk)
IkarusTrojan.Win32.VMProtect
FortinetMalicious_Behavior.SB
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.4131324803?

Malware.AI.4131324803 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment