Malware

Malware.AI.4210049562 removal instruction

Malware Removal

The Malware.AI.4210049562 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4210049562 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Malware.AI.4210049562?


File Info:

name: E9256E26BF5F5A2AF360.mlw
path: /opt/CAPEv2/storage/binaries/c67ca2af7055beae14544fbe54a36a2c907be2125a9e75ef0a804a34f05dea7d
crc32: 550E24F2
md5: e9256e26bf5f5a2af360fc7f28ea9750
sha1: 8d753efcb6a4b0f059e1d9ce94a63e6b91bb712c
sha256: c67ca2af7055beae14544fbe54a36a2c907be2125a9e75ef0a804a34f05dea7d
sha512: d010b5bbada7c0b18c2d499abe7152c1b9ba0a7acd46702690acf0c129b46e462c9720cbff3e6b4493f23a8d49f916540d945ef9f45e623a1ef8328cefa053c4
ssdeep: 12288:9engaiA34JJqUqiQQLL6Z6iDXU3h2lDNS5c1+ieWHXQe2x:9enCAoJJqUqiQQLWZMYlDGc+WHXQR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16705AF2171C2C4B7D5A3027609FA977AA77ABD150B3196C7B7C8AF5D6E324C2CE35202
sha3_384: 1f573668642e8c4cc533086ba690b75dc5f2ad6840632e0d5b93da2c758e25438501ec50bf49fc9d277c88bc5aafee5c
ep_bytes: 558bec6aff68503f410068b05d400064
timestamp: 2009-06-05 07:15:57

Version Info:

0: [No Data]

Malware.AI.4210049562 also known as:

LionicTrojan.Win32.Banito.4!c
FireEyeGeneric.mg.e9256e26bf5f5a2a
McAfeeArtemis!B53FD5DBF5FF
CylanceUnsafe
ZillyaTrojan.Agent.Win32.141647
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004ea7041 )
AlibabaTrojan:Win32/Banito.4d626dd4
Cybereasonmalicious.cb6a4b
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.VUN
APEXMalicious
Paloaltogeneric.ml
NANO-AntivirusTrojan.Win32.Banito.crbeps
AvastWin32:Malware-gen
ComodoSuspicious@#1dru000tt2lj
DrWebTrojan.MulDrop5.56091
McAfee-GW-EditionBehavesLike.Win32.Dropper.cm
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Banito.d
WebrootW32.Gen.BT
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.B28
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaE.34682.YqW@aOBnJzcj
MAXmalware (ai score=94)
VBA32Trojan.Banito
MalwarebytesMalware.AI.4210049562
TrendMicro-HouseCallTROJ_GEN.R03BH0CIO22
RisingMalware.Undefined!8.C (TFE:5:9E0alJKjhcC)
YandexTrojan.Banito!aFPGy+ENmO8
IkarusTrojan.Win32.Banito
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banito.H!tr
AVGWin32:Malware-gen
PandaTrj/Chgt.AD

How to remove Malware.AI.4210049562?

Malware.AI.4210049562 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment