Malware

How to remove “Malware.AI.4165165244”?

Malware Removal

The Malware.AI.4165165244 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4165165244 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Attempts to connect to a dead IP:Port (190 unique times)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Binary compilation timestomping detected

How to determine Malware.AI.4165165244?


File Info:

name: 99EC20548100944201B1.mlw
path: /opt/CAPEv2/storage/binaries/0a609d0b53f55722baef3fdd03efbb37a8f0035e9336aded1d18013e29422b6a
crc32: B5671218
md5: 99ec20548100944201b1d90997fc619d
sha1: 6a21647001c30ac23588b6283dca09c14194b409
sha256: 0a609d0b53f55722baef3fdd03efbb37a8f0035e9336aded1d18013e29422b6a
sha512: c1fe9ec128e347d5cfe6acaf4a48361074654293deafbc495dc7b49133b051cc5b8da39d1fcb665263683f8334544c723438ae19e91bdafa7e345d99d0831e81
ssdeep: 1536:JM7EK+cTMFW+fMRiZzS0M/pjKXU783pcr83pcaOrh:+7BaFW+flA0mpmkCpcypc7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16483E755B6C98740F59A58B050FFFAA443F231E79BF29A892F5C428C0FE0BD12D8465E
sha3_384: 1dc095494f5a308afe8559bbeed1435bd94080e9cafcea6e1e5b8430a0d77b67594356b73417aeaa8b054518690bcb4e
ep_bytes: ff250020400000000000000000000000
timestamp: 2090-08-07 01:17:34

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: csrss
FileVersion: 1.0.0.2
InternalName: csrss.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: csrss.exe
ProductName: csrss
ProductVersion: 1.0.0.2
Assembly Version: 1.0.0.0

Malware.AI.4165165244 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.92507
FireEyeGeneric.mg.99ec205481009442
McAfeeArtemis!99EC20548100
CylanceUnsafe
K7AntiVirusTrojan ( 005082b31 )
K7GWTrojan ( 005082b31 )
Cybereasonmalicious.481009
BitDefenderThetaGen:NN.ZemsilF.34114.eq0@aSOxtre
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.SHX
KasperskyHEUR:Trojan.MSIL.Fsysna.gen
BitDefenderGen:Variant.Lazy.92507
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Lazy.92507
SophosML/PE-A
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Suspicious PE
EmsisoftGen:Variant.Lazy.92507 (B)
APEXMalicious
GDataGen:Variant.Lazy.92507
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Kryptik.hjuqp
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Lazy.92507
MAXmalware (ai score=83)
MalwarebytesMalware.AI.4165165244
IkarusTrojan.Dropper
FortinetMSIL/Kryptik.SHX!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.4165165244?

Malware.AI.4165165244 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment