Malware

Malware.AI.4145269389 removal guide

Malware Removal

The Malware.AI.4145269389 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4145269389 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Malware.AI.4145269389?


File Info:

name: 783908E259119A51276B.mlw
path: /opt/CAPEv2/storage/binaries/aad8dcf95f97b52c75e96185d6202cd6bdc0eff2514aa7bf67b510a29d80bdaa
crc32: 2B9AF107
md5: 783908e259119a51276b4ff9ddeb427a
sha1: 26bef32debe19efd8238e98263beeba97e76e388
sha256: aad8dcf95f97b52c75e96185d6202cd6bdc0eff2514aa7bf67b510a29d80bdaa
sha512: f4794bad5bb1ce2e4d1a59fa83b9a40101e9976004954ee95b82d1442b63863808a7adbc55c40b50c3a9498f38885213032e17721307eb802b83c3b601e79d2f
ssdeep: 98304:vJa/eNBIukBbV+T00TJDAWLYn4PPjsnCv:ha/eNOumRUEcYn4njsnCv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D26BF2377B2C076C55E077A696D532C61B526900F74C8C7E3E42F2EBF305D2963AA4A
sha3_384: dfa43ff663503896fd4e5e31f8904a79007a22157c66e85209e70433fcd93450de204c12a8495f08e5b54d9966ecfff3
ep_bytes: 558bec6aff6828524a00686cac490064
timestamp: 2017-10-03 16:52:16

Version Info:

0: [No Data]

Malware.AI.4145269389 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38833585
FireEyeGeneric.mg.783908e259119a51
ALYacTrojan.GenericKD.38833585
CylanceUnsafe
SangforRiskware.Win32.FakeRansom.gen
K7AntiVirusAdware ( 005835081 )
K7GWAdware ( 005835081 )
Cybereasonmalicious.debe19
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyVHO:Hoax.Win32.FakeRansom.gen
BitDefenderTrojan.GenericKD.38833585
Ad-AwareTrojan.GenericKD.38833585
SophosGeneric PUA CG (PUA)
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
EmsisoftTrojan.GenericKD.38833585 (B)
GDataWin32.Trojan.Agent.WP
Antiy-AVLTrojan/Generic.ASCommon.218
ZoneAlarmVHO:Hoax.Win32.FakeRansom.gen
CynetMalicious (score: 100)
McAfeeArtemis!783908E25911
MAXmalware (ai score=82)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.4145269389
TrendMicro-HouseCallTROJ_GEN.R002H0CAV22
RisingTrojan.Kryptik!1.B3E8 (CLOUD)
FortinetW32/CoinMiner.WP!tr
BitDefenderThetaGen:NN.ZexaF.34182.@pW@a4V6NKi
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.4145269389?

Malware.AI.4145269389 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment