Malware

Malware.AI.4209989522 information

Malware Removal

The Malware.AI.4209989522 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4209989522 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Malware.AI.4209989522?


File Info:

name: C606146B74D361E894AA.mlw
path: /opt/CAPEv2/storage/binaries/c24367e4f6a1b95af2732482015d593287a3993c30e6a30268e7ffb5041af419
crc32: B94C156E
md5: c606146b74d361e894aa86fcc1ae2c76
sha1: 8ac5a02d93b2a94cae8e0aa63adc6a8a618e92cd
sha256: c24367e4f6a1b95af2732482015d593287a3993c30e6a30268e7ffb5041af419
sha512: b7562e5db565167b9bb74b72c8dcf3705c2115edc24d985a2f9c0755f600d1bdbcd039a6df97b70eb535f2cf54b464f4a73fa9501f7cfc36a1b7636578baf7d4
ssdeep: 1536:b3ScSeuCQ5CvP3ErbK0GsA1Irn6ykkXERklFceLnFaswUemjmh5WGiir5Gnw:7SleucPUXKhsmIGZkXYUJFg5fRiaQnw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1239302D437BCBBC1E08F8F74709EB90BB089A52196ED811B2505530FDBE8097660B67B
sha3_384: e1d5cc0b9b1d3811a8ed68ffc623dca39e8bea4aa6e104e73a4a00a547636bb83e8ea135a234f6c846e44056ebbbaef6
ep_bytes: 60be007046008dbe00a0f9ff57eb0b90
timestamp: 2014-12-02 16:57:06

Version Info:

0: [No Data]

Malware.AI.4209989522 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGeneric.Dacic.EA08C894.A.E0C6F34E
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.c606146b74d361e8
CAT-QuickHealRisktool.Flystudio.17330
ALYacGeneric.Dacic.EA08C894.A.E0C6F34E
CylanceUnsafe
ZillyaTrojan.Scar.Win32.86485
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BaiduWin32.Trojan-PSW.QQPass.p
VirITTrojan.Win32.Generic.EJO
CyrenW32/QQPass.AF.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.QQPass.OUO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.ieeg
BitDefenderGeneric.Dacic.EA08C894.A.E0C6F34E
NANO-AntivirusTrojan.Win32.Scar.dkantc
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Qqpass.16000304
Ad-AwareGeneric.Dacic.EA08C894.A.E0C6F34E
SophosML/PE-A + Troj/Agent-BBAC
ComodoTrojWare.Win32.PWS.QQpass.WE@5reqqq
DrWebTrojan.DownLoader11.50159
VIPREGeneric.Dacic.EA08C894.A.E0C6F34E
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.EA08C894.A.E0C6F34E (B)
IkarusTrojan.Win32.Dynamer
JiangminTrojan/Scar.bdgb
AviraTR/Spy.Gen7
Antiy-AVLTrojan/Generic.ASMalwIH.162
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Agent.gen
GDataWin32.Trojan-Stealer.BlackMoon.D
GoogleDetected
AhnLab-V3Trojan/Win32.Stealer.R143066
Acronissuspicious
McAfeeGenericRXQQ-LZ!119563A6F475
MAXmalware (ai score=84)
VBA32Trojan.Scar
MalwarebytesMalware.AI.4209989522
YandexTrojan.Scar!Lp0YtmaDpP4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GameHack.AX!tr
BitDefenderThetaAI:Packer.6750655F23
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.b74d36
PandaTrj/Genetic.gen

How to remove Malware.AI.4209989522?

Malware.AI.4209989522 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment