Malware

Malware.AI.4190541064 removal instruction

Malware Removal

The Malware.AI.4190541064 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4190541064 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.4190541064?


File Info:

name: 94F51EE179249F698F2B.mlw
path: /opt/CAPEv2/storage/binaries/55c6cdb0f7fb678884e51fd58fff0740a6aeb1309bc6efa3e20c20b31a365808
crc32: 540E1E89
md5: 94f51ee179249f698f2b42f2c5aaaee3
sha1: 5a34264fe10d99f5ac80a91d646a891a364d1565
sha256: 55c6cdb0f7fb678884e51fd58fff0740a6aeb1309bc6efa3e20c20b31a365808
sha512: 5ce2faa3a4eea8aa17b8ed81049d012ca86503b3902bbf2f77acc91c25c65f5a954feb6e8a3f7afc75c3fa737aecdfde8a520ef1ae389250ca9af05b4cb7ec29
ssdeep: 49152:TuzqQFdDBKxeBbk/aaMjk6P8Xwr43ilpDL9wMnBm6w30IAw+W7SCsT:Tu2QFtrBboanI6PIwrjpDLpBmDD70
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118D5F106F7E9741EF4A75EFA64B0A63155A2BF064F0DC75ECD38302D1A723818C61AA7
sha3_384: 2e8b25e8f94eae714d2e6162198d3e3e511d5a4d60243363bd396431aea6e4f90d689edf8a24a186ec177a3d0f1c1001
ep_bytes: ff2500206300193000000084a303000a
timestamp: 2080-05-12 23:55:00

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: MBTools
FileVersion: 1.0.0.0
InternalName: MBTools.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: MBTools.exe
ProductName: MBTools
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4190541064 also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.94f51ee179249f69
CylanceUnsafe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.ACR
Paloaltogeneric.ml
AvastWin32:MalwareX-gen [Trj]
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
SophosMal/Generic-S
IkarusTrojan.Win32.VMProtect
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!94F51EE17924
MalwarebytesMalware.AI.4190541064
APEXMalicious
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
AVGWin32:MalwareX-gen [Trj]
PandaTrj/Orbond.A
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.4190541064?

Malware.AI.4190541064 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment