Malware

How to remove “Malware.AI.4216144738”?

Malware Removal

The Malware.AI.4216144738 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4216144738 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Malware.AI.4216144738?


File Info:

name: C5F4EAD837A534E71273.mlw
path: /opt/CAPEv2/storage/binaries/0b7dd5eedf49c6fabc36ec2dc3ed89a112ad2639412767bca4a54341cff5d4d5
crc32: C76CDA5E
md5: c5f4ead837a534e71273a6ba70224c0c
sha1: a623641d3bcd646f43c9df50763344a2f4cd3ede
sha256: 0b7dd5eedf49c6fabc36ec2dc3ed89a112ad2639412767bca4a54341cff5d4d5
sha512: 71d46551c9050b588c949f87294f30f4e74ac9ec51aa84d5760a9098719111c9a26c9ae05384d620f0874e9875f2536126da25498de2ae7a4f8d30b7ce73c48b
ssdeep: 12288:8Uv3yzf9l1u1E0waXmS9C/rcuaawncJrJrPBJbw8px0gz7c5aIC9DVkK5aZTwdt1:8Uvw1uMaXJc/rhaby9J6ixjsadp5xpw2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196252303FB62A03DE9F00FB098E97533C33E7D6E2A14E77E71B8481E0D666411A94B95
sha3_384: 97ce017e53121f2c0a7082996be1e9f3e5a82e2d550cbe82d83ce5dea8562a30a4be64ba7514f1bbd39aa54cc177dcba
ep_bytes: 558bec83c4c053565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.4216144738 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanApplication.MailBomber.F
FireEyeApplication.MailBomber.F
CylanceUnsafe
SangforTrojan.Win32.Fareit.ml
K7AntiVirusDoS-Trojan ( 004c77111 )
AlibabaTrojan:Win32/MailSpam.b6476385
K7GWDoS-Trojan ( 004c77111 )
Cybereasonmalicious.837a53
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Flooder.MailSpam.Bomber
BitDefenderApplication.MailBomber.F
NANO-AntivirusTrojan.Win32.MBomber.cythds
AvastWin32:PUP-gen [PUP]
ComodoMalware@#18olt8o9by4vv
DrWebFDOS.MBomber
VIPRETrojan.Win32.Generic!BT
EmsisoftApplication.MailBomber.F (B)
GDataApplication.MailBomber.F
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.755B5D
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Fareit!ml
BitDefenderThetaGen:NN.ZelphiF.34212.AHW@a44JMuji
MAXmalware (ai score=86)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.4216144738
RisingTrojan.Win32.Generic.12596D0A (C64:YzY0OkJCVNhpN06H)
AVGWin32:PUP-gen [PUP]

How to remove Malware.AI.4216144738?

Malware.AI.4216144738 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment