Malware

About “Malware.AI.4165211626” infection

Malware Removal

The Malware.AI.4165211626 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4165211626 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Malware.AI.4165211626?


File Info:

name: A4B27ADAF5E8DF798801.mlw
path: /opt/CAPEv2/storage/binaries/ef7b82d87c08093fbdac0dc97daa6b704732414a5beea87c5d3781ae836460e4
crc32: 86A65065
md5: a4b27adaf5e8df7988015fadf1acd081
sha1: 4dc5a57f64245878026ce411f132d7226fc62273
sha256: ef7b82d87c08093fbdac0dc97daa6b704732414a5beea87c5d3781ae836460e4
sha512: 2d2c7fd9c2945291d2b14c4b3ffbfc6458a938089ee1f0411fd7126b27d22db4b6bd849ec164e6616913f10f688b43cb5c3f2a3b609822500af450a5db24a52c
ssdeep: 3072:kd6LNdParoQCejOF9JclHBHI1mMF/SSRT9N0FRqDzg0BdvJGgp:kUZorRCejOVSHI1R/SSh9NtDt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12D248D307A66C036D69700B399D997BA51197A31572250C7FBA80F7C6EB06F36B3930B
sha3_384: e223a9d2dadb356fa18a53d448295b34920c6788101c7b856416758199671a1e94aca68c0fcbc166cf43bcc3f1018638
ep_bytes: e8c4530000e989feffffb8261a4200a3
timestamp: 2015-03-13 06:31:47

Version Info:

0: [No Data]

Malware.AI.4165211626 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a4b27adaf5e8df79
McAfeePUP-XEF-PS
MalwarebytesMalware.AI.4165211626
SangforPUP.Win32.Generic.frdE
AlibabaAdWare:Win32/ConvertAd.291e4a6a
Cybereasonmalicious.af5e8d
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Adware.ConvertAd.CZ
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.ConvertAd.bkug
BitDefenderApplication.Generic.1176594
NANO-AntivirusRiskware.Win32.ConvertAd.dqfjie
MicroWorld-eScanApplication.Generic.1176594
AvastWin32:ConvertAd-BG [Adw]
TencentMalware.Win32.Gencirc.114cbbf7
Ad-AwareApplication.Generic.1176594
EmsisoftApplication.Generic.1176594 (B)
ComodoApplicUnwnt@#3liq9o55exdz2
F-SecureAdware.ADWARE/ConvertAd.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosGeneric PUA EN (PUA)
SentinelOneStatic AI – Suspicious PE
GDataApplication.Generic.1176594
JiangminAdWare.ConvertAd.pma
eGambitUnsafe.AI_Score_98%
AviraADWARE/ConvertAd.Gen
MAXmalware (ai score=76)
Antiy-AVLGrayWare[AdWare]/Win32.ConvertAd
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Wacatac.A!ml
BitDefenderThetaGen:NN.ZexaF.34062.muW@aOC0KVai
ALYacApplication.Generic.1176594
VBA32BScope.Adware.ConvertAd
TrendMicro-HouseCallTROJ_GEN.R002C0PKQ21
RisingTrojan.Generic@ML.94 (RDML:qcA0AKskOTU//qSgYHiKQA)
YandexPUA.ConvertAd!HC6VNIy2kkw
IkarusPUA.ConvertAd
FortinetRiskware/ConvertAd
WebrootW32.Malware.Gen
AVGWin32:ConvertAd-BG [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.4165211626?

Malware.AI.4165211626 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment