Malware

How to remove “Malware.AI.4192478828”?

Malware Removal

The Malware.AI.4192478828 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4192478828 virus can do?

  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.4192478828?


File Info:

name: 38475BFED6985A7B6DE4.mlw
path: /opt/CAPEv2/storage/binaries/f2f9c36da0d867accae90afe26c912bf58bbab702eb49f5eb01e324a1d5fe0b9
crc32: 6BA6C118
md5: 38475bfed6985a7b6de40b474a3baede
sha1: 3774832073e06870e68d8d4690e69d5f63129202
sha256: f2f9c36da0d867accae90afe26c912bf58bbab702eb49f5eb01e324a1d5fe0b9
sha512: e1856d0378acc4170ab7b789af394e887e5ec150069ff3f7bbe5451a4cc377cc607a6f685fbe47c9af170592cbd2a020013b6cbd84900c4967353f59238c4e31
ssdeep: 3072:DL2xtoDC6HbWIA5HGhT3O7w5OcGxmWVCi5fxbExAbPrpGw8FydD2MCuwO8px:hSIA1AT+UBiPVCi55bdbP9GwCUKMCux
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A264F1412AE30167F585863081A64DC27B7F2F3B3CE2D15FCF64395A3ABD2A19861B71
sha3_384: 0c08c4c07c71a0e30d88a02f90bc019b5e9fd1440aa9437167aa7419d290412eb8ab82f60d608ab642100c5cef61df3a
ep_bytes: 558bec6aff68d0504000682c1d400064
timestamp: 1981-01-11 11:13:52

Version Info:

CompanyName: Microsoft Corporation
FileDescription: SQL Server 6.5 Setup Stub
FileVersion: 2000.080.0194.00
InternalName: stub
LegalCopyright: © 1988-2000 Microsoft Corp. All rights reserved.
OriginalFilename: stub.exe
ProductName: Microsoft SQL Server
ProductVersion: 8.00.194
LegalTrademarks: Microsoft® 是 Microsoft Corporation 的注册商标。Windows(TM) 是 Microsoft Corporation 的注册商标
Translation: 0x0804 0x04b0

Malware.AI.4192478828 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.470891
FireEyeGeneric.mg.38475bfed6985a7b
McAfeeArtemis!38475BFED698
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
Cybereasonmalicious.073e06
BitDefenderThetaGen:NN.ZexaF.34084.ty0@au!eeCbb
CyrenW32/Trojan.TXCZ-4247
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H09LA21
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.470891
AvastFileRepMalware
TencentWin32.Trojan.Dovqplay.Ljkh
Ad-AwareGen:Variant.Bulz.470891
SophosML/PE-A + Mal/Emogen-E
McAfee-GW-EditionBehavesLike.Win32.Worm.fm
EmsisoftGen:Variant.Bulz.470891 (B)
IkarusVirus.Win32.Virut
GDataGen:Variant.Bulz.470891
MaxSecureTrojan.Malware.117999939.susgen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.470891
MalwarebytesMalware.AI.4192478828
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Emogen.E
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.4192478828?

Malware.AI.4192478828 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment