Malware

Should I remove “Malware.AI.4211715366”?

Malware Removal

The Malware.AI.4211715366 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4211715366 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Emumerates physical drives
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4211715366?


File Info:

name: CE1C2630062FDA0EDF07.mlw
path: /opt/CAPEv2/storage/binaries/5792836fb0ac02da8a7c053dfb07522a953877724b63e8918187e5a4a4413ff5
crc32: DAEC6032
md5: ce1c2630062fda0edf0709317efa1416
sha1: 025cf1772b5f9d7bd76be614aadd261a35708da4
sha256: 5792836fb0ac02da8a7c053dfb07522a953877724b63e8918187e5a4a4413ff5
sha512: bd8c25580762f536701da302797713abbf99c045c813826a1e9f7176f47b007ffbe70abe72ee70ece49c6f02869fe5e0e303afa14ce8d8e84f92e28eb52b6eb1
ssdeep: 3072:taEU79Zz93t/fPBbsrB9oxHUVwpFrOwGQJF2RVTrykX2eO:taZ9Zzv/fPBbsN9oxdRmRVkL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AFC30216AC055BD0C9577EBC00C12A2D6F7CA5B6BFF6425FC980909909FECBAFA24412
sha3_384: c99d109ad4855065603881c98ca795575a80e136e7965965abe0aecc3cb9001c5ed43510cf53889117f636570f664e31
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2016-06-25 08:27:48

Version Info:

Translation: 0x0804 0x04b0
CompanyName: 巴比伦IT
ProductName: 无敌短信轰炸机
FileVersion: 2.02.0001
ProductVersion: 2.02.0001
InternalName: 无敌短信轰炸机
OriginalFilename: 无敌短信轰炸机.exe

Malware.AI.4211715366 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Magania.tn6B
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.68227995
FireEyeGeneric.mg.ce1c2630062fda0e
SkyhighBehavesLike.Win32.Generic.cc
McAfeeRDN/Generic.dx
Cylanceunsafe
ZillyaTrojan.Generic.Win32.1846822
SangforTrojan.Win32.Agent.V45s
Cybereasonmalicious.72b5f9
tehtrisGeneric.Malware
CynetMalicious (score: 99)
APEXMalicious
BitDefenderTrojan.GenericKD.68227995
EmsisoftTrojan.GenericKD.68227995 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.GenericKD.68227995
Trapminemalicious.high.ml.score
SophosMal/Generic-S
VaristW32/Trojan.OJEY-1048
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Zpevdo
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D411139B
GDataTrojan.GenericKD.68227995
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C4576811
ALYacTrojan.GenericKD.68227995
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
MalwarebytesMalware.AI.4211715366
TrendMicro-HouseCallTROJ_GEN.R002H09KF23
SentinelOneStatic AI – Malicious PE
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4211715366?

Malware.AI.4211715366 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment