Malware

Malware.AI.4217992045 removal instruction

Malware Removal

The Malware.AI.4217992045 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4217992045 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a file

How to determine Malware.AI.4217992045?


File Info:

name: D01FF6F0BFB1B515E8BA.mlw
path: /opt/CAPEv2/storage/binaries/fec657a19356753008b0f477083993aa5c36ebaf7276742cf84bfe614678746b
crc32: B81CA812
md5: d01ff6f0bfb1b515e8ba10a453c74d53
sha1: 3c67937b4b913a552c608709b2d0818a3052f35f
sha256: fec657a19356753008b0f477083993aa5c36ebaf7276742cf84bfe614678746b
sha512: e5f5f80d6588af012210d441faa462041c4351e1378b35a313bfe5d245bf8deba7590e0c36eb8ea751de28d3794b321b30808189c248429d22d6398481203178
ssdeep: 3072:T6snTh5vMUWR6U5kwvvt+fzf4ANDCOSp3CvdHOcJn+UAQBR75:Tvh5I5hQUeSpwlrJiAb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194148E9D374D5FA7C5A6867688D3A19583B4C0B7D3E3FB4F50E80C20A812BE9164F897
sha3_384: 06b830e0e3ac862bf85373d9b44c78d9da0643d4b5337da1c752482d5cf33db52957f842767219339b3d9063fd0ed42e
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-05-10 18:02:51

Version Info:

Comments: CCleaner
CompanyName: Piriform Ltd
FileDescription: CCleaner
FileVersion: 5, 18, 00, 5607
InternalName: ccleaner
LegalCopyright: Copyright © 2005-2016 Piriform Ltd
OriginalFilename: ccleaner.exe
ProductName: CCleaner
ProductVersion: 5, 18, 00, 5607
Translation: 0x0409 0x04b0

Malware.AI.4217992045 also known as:

LionicTrojan.Win32.Generic.lV2U
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILMamut.5383
FireEyeGeneric.mg.d01ff6f0bfb1b515
SkyhighGeneric.dwa
McAfeeGeneric.dwa
Cylanceunsafe
ZillyaTrojan.Agent.Win32.807286
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004efb951 )
AlibabaTrojan:MSIL/MultiPacked.26f6bacd
K7GWTrojan ( 004efb951 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitIL:Trojan.MSILMamut.D1507
BitDefenderThetaGen:NN.ZemsilF.36792.lm1@aiXFqYdi
VirITTrojan.Win32.Dnldr24.DIOI
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Agent.AIX
APEXMalicious
KasperskyTrojan.MSIL.Agent.fpsg
BitDefenderIL:Trojan.MSILMamut.5383
NANO-AntivirusTrojan.Win32.Agent.eoweer
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114a1fd2
EmsisoftIL:Trojan.MSILMamut.5383 (B)
F-SecureHeuristic.HEUR/AGEN.1304208
DrWebTrojan.DownLoader24.58508
VIPREIL:Trojan.MSILMamut.5383
TrendMicroTROJ_GEN.R002C0PHR20
Trapminemalicious.high.ml.score
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.mvqj
WebrootW32.Trojan.Genkd
VaristW32/Agent.TDRJ-3480
AviraHEUR/AGEN.1304208
Antiy-AVLTrojan[APT]/Win32.Molerats
Kingsoftmalware.kb.c.876
MicrosoftTrojan:Win32/Vagger!rfn
ZoneAlarmTrojan.MSIL.Agent.fpsg
GDataIL:Trojan.MSILMamut.5383
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Agent.C3636055
ALYacTrojan.MSIL.Agent.658868
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.4217992045
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PHR20
RisingTrojan.Agent!8.B1E (CLOUD)
YandexTrojan.Agent!DLncGzJuZbE
IkarusTrojan.MSIL.MultiPacked
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Generic.AP.9A7BE4!tr
AVGWin32:Malware-gen
Cybereasonmalicious.b4b913
DeepInstinctMALICIOUS

How to remove Malware.AI.4217992045?

Malware.AI.4217992045 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment