Malware

What is “Malware.AI.4212285131”?

Malware Removal

The Malware.AI.4212285131 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4212285131 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.4212285131?


File Info:

name: E2CC80C46B602857DF87.mlw
path: /opt/CAPEv2/storage/binaries/f66ac117865662b79e967544f7fdb3a7af37baf5728381a5cd4a705ae59253bb
crc32: F55344BF
md5: e2cc80c46b602857df873a46ece840db
sha1: 84ee692f65960f8df04c39ec391c63d253c9c212
sha256: f66ac117865662b79e967544f7fdb3a7af37baf5728381a5cd4a705ae59253bb
sha512: 61ca61f711d3e48567b38f48c794a3d044f03c42ae588d1ce991508a5dff60fb1528075d9a28bbe7ff3f829ecb8952e97c2430b81226079e3e5af1fdb7f062d3
ssdeep: 768:u2LqGpkAHRCXeyFAy/7gMQRHp6Xx83hBvyygxK4jNE6Q3Qxjhn:LCAOe7QL6p3hQy94S6QglN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C003E1A8A3F69300D1DD0734177E8A0F8D799C6B2E6C27868068376FCD739554A3C55B
sha3_384: ced6dc1a19a8874fb5756b8fc585765ad2ef0920ae3e54b29435a585042c6cc9a778e9e2dd162c0976c6e90e39d1e12d
ep_bytes: 60be003041008dbe00e0feff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Administractor
FileVersion: 4.3.1.46
InternalName: SysUser32
LegalCopyright: Copyright (C) Microsoft Corp. 2001-2005
LegalTrademarks:
OriginalFilename:
ProductName: Microsoft(R) Windows NT(R) Operating System
ProductVersion: 4.1.0.45
Comments:
Translation: 0x0804 0x03a8

Malware.AI.4212285131 also known as:

MicroWorld-eScanGen:Trojan.Heur.fG0@rGLAwmmb
McAfeeRDN/Generic.grp
CylanceUnsafe
K7AntiVirusTrojan ( 005376ae1 )
AlibabaTrojan:Win32/Nilage.4c12c9e0
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.46b602
CyrenW32/Threat-SysVenFak-based!Maxi
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Trojan.Heur.fG0@rGLAwmmb
AvastFileRepMetagen [Malware]
SophosMal/Generic-R + Mal/Behav-160
ComodoTrojWare.Win32.Spy.Banker.Gen@1qlojk
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PLA21
McAfee-GW-EditionBehavesLike.Win32.Fake.nc
FireEyeGen:Trojan.Heur.fG0@rGLAwmmb
EmsisoftGen:Trojan.Heur.fG0@rGLAwmmb (B)
GDataGen:Trojan.Heur.fG0@rGLAwmmb
JiangminBackdoor/Delf.kjp
Antiy-AVLTrojan/Generic.ASMalwS.847F6B
MicrosoftProgram:Win32/Wacapew.C!ml
ALYacGen:Trojan.Heur.fG0@rGLAwmmb
MAXmalware (ai score=80)
MalwarebytesMalware.AI.4212285131
TrendMicro-HouseCallTROJ_GEN.R002C0PLA21
eGambitUnsafe.AI_Score_95%
FortinetW32/PossibleThreat
BitDefenderThetaAI:Packer.BF02D0EB1C
AVGFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.117992579.susgen

How to remove Malware.AI.4212285131?

Malware.AI.4212285131 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment