Malware

Malware.AI.4151295878 removal

Malware Removal

The Malware.AI.4151295878 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4151295878 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4151295878?


File Info:

name: 12C96D4A4402C3938561.mlw
path: /opt/CAPEv2/storage/binaries/5ccd3b49e679dec78cfa8c28b41de28225ec8312baf6461b5289950711d3a375
crc32: 58FD3559
md5: 12c96d4a4402c39385617eeaacb9a1f4
sha1: acf6b63011316f7504c174cc87b43ff40a9763c4
sha256: 5ccd3b49e679dec78cfa8c28b41de28225ec8312baf6461b5289950711d3a375
sha512: 2e6bc211389a0f3eda4470b772c6f844200c7029d610b2c5db82b6d7c35c31ce8ecc40eb86da0f6325647df6033ccfe5048f1b5c0e6aa9017e531a6a50222c19
ssdeep: 49152:Y6tCm1p37ZGYJZnLsTYnZzKllpBlqgBbyuDymZKX0IfW8cIMhJJY+eYu3bs:AS37vZnLsToKLTggBpD/ZKkIefIkF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171C502C2FC8666F0DC358836915B48525A7F5C3DC6455CE3BAC8BA3B8077492613AE3B
sha3_384: 60ce68d07f9a2e6d6a3e916dea1c2f160224601aa4c82e66e1fa067bb85c8859b1596787ae029372fbd74a89b80db4e5
ep_bytes: e89e040000e98efeffff3b0dc8a14300
timestamp: 2018-06-24 15:04:40

Version Info:

0: [No Data]

Malware.AI.4151295878 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Uztuby.1
FireEyeGeneric.mg.12c96d4a4402c393
ALYacTrojan.Uztuby.1
K7AntiVirusTrojan ( 005239691 )
K7GWRiskware ( 0049db191 )
CrowdStrikewin/malicious_confidence_60% (W)
ArcabitTrojan.Uztuby.1
CyrenW32/Trojan.DZQ.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.NoobyProtect.M suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Metla.a
BitDefenderTrojan.Uztuby.1
Ad-AwareTrojan.Uztuby.1
SophosATK/SwrortPk-B
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
VIPRETrojan.Uztuby.1
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Uztuby.1 (B)
SentinelOneStatic AI – Malicious SFX
AviraHEUR/AGEN.1227225
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASBOL.C6B4
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Packed.NoobyProtect.B
GoogleDetected
McAfeeArtemis!12C96D4A4402
MalwarebytesMalware.AI.4151295878
RisingTrojan.Tiggre!8.ED98 (TFE:5:imw1H4gFoTF)
YandexTrojan.GenAsa!3rJDnpC1WEY
IkarusTrojan.Win32.Swrort
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34682.Ov1@aiXTJTmi
Cybereasonmalicious.a4402c

How to remove Malware.AI.4151295878?

Malware.AI.4151295878 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment