Malware

What is “Malware.AI.4149076241”?

Malware Removal

The Malware.AI.4149076241 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4149076241 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script process created a new process
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4149076241?


File Info:

name: 8875BC6C92A5534BCD7B.mlw
path: /opt/CAPEv2/storage/binaries/20f06de888efad4a9273a33982af70757f524a7c374c1d495ef11cfcc13aaa6e
crc32: 015CE639
md5: 8875bc6c92a5534bcd7b336331e901c4
sha1: 0c0cdedf17ac4c29ff07edf3e506fedf165655e4
sha256: 20f06de888efad4a9273a33982af70757f524a7c374c1d495ef11cfcc13aaa6e
sha512: 6db6650bddbc8be277fd20da08f468a31390748254ef74c74b72c2f87950e575ad4d01ddefb7fb6e3743ae0b1185f0e6de8a20b4d5b890cc3c83283dbd4f41e1
ssdeep: 24576:h2G/nvxW3WH0YM6VBBhczc5ra0JWNwL/T+4a:hbA3FYMgVJo9n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1586538027A48C915D0391736E5EFC13847A8AE512A22DB1A7EDE3F6F75723A31C0D5CA
sha3_384: 0a6526b65a99e72dabd3a872d909337284cbc06dbad0734e53f1a5ce9ffb9c9af5c1c476382b092b3e2c20dacf66005c
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Malware.AI.4149076241 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Uztuby.17
FireEyeGeneric.mg.8875bc6c92a5534b
McAfeeGenericRXQV-TR!4CCEA3ADC2CE
SangforSuspicious.Win32.Save.a
AlibabaTrojanSpy:MSIL/Stealer.058a6fdb
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.Uztuby.17
AvastWin32:SpywareX-gen [Trj]
EmsisoftTrojan.Uztuby.17 (B)
DrWebBackDoor.QuasarNET.5
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
SophosMal/RarMal-R
AviraHEUR/AGEN.1141820
MAXmalware (ai score=89)
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
GDataWin32.Trojan.BSE.1CL7UZW
BitDefenderThetaGen:NN.ZemsilF.34182.6q0@a0Pxtdgi
ALYacIL:Trojan.MSILZilla.9872
MalwarebytesMalware.AI.4149076241
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:pQV0gPm8+OjlQFfeegde7w)
SentinelOneStatic AI – Malicious SFX
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DEK!tr
AVGWin32:SpywareX-gen [Trj]
Cybereasonmalicious.c92a55

How to remove Malware.AI.4149076241?

Malware.AI.4149076241 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment