Malware

How to remove “Malware.AI.4224248792”?

Malware Removal

The Malware.AI.4224248792 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4224248792 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4224248792?


File Info:

name: 30BE40B48DD6B850F9C3.mlw
path: /opt/CAPEv2/storage/binaries/62699a921436984243360c9ef22c650a5f19edf750a52cb4998d3d311971c448
crc32: 5A5D6217
md5: 30be40b48dd6b850f9c3f86d0b570e3a
sha1: 11f82cf8a6668a5ce10e01cd075791ff992bb397
sha256: 62699a921436984243360c9ef22c650a5f19edf750a52cb4998d3d311971c448
sha512: f45f8556dcbba9a9a5a4e4259305bd5b152c0fc7398b49993a33ebb74a39ce1cc151a60302af4c42a921baf44d8a653c8486f5081394aac1c7710379ef907568
ssdeep: 12288:X/FXBriGA4iri0uVD+v9GZ1c2obY7PLbmzKsi3d:XHHADr/EDq9G1oczZsi3d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CBC42344BB3CE214E4F8A3F8DD99BBF62F42ED584C20D7372D44BB8696B1B166486301
sha3_384: 2f6b9f17b3b084f7a5e18e48810ef61c3897a8f7647f39c0279d55e900d5ae3a8304bc9c320726a0ebe9b1dbaaa89a39
ep_bytes: 6801d04b00e801000000c3c30d3ff5f7
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: (C)2000-2006,Gotop Corp.China
FileDescription: 简体中文 Telnet
FileVersion: 1.1.4.271
InternalName: 简体中文 Telnet
LegalCopyright: (C)2000-2006,Gotop Corp.China
LegalTrademarks: 福建国通科技
OriginalFilename: Gtelnet.exe
ProductName: 国通科技简体中文 Telnet
ProductVersion: 1.01
Comments: www.gotop.net.cn
Translation: 0x0804 0x03a8

Malware.AI.4224248792 also known as:

LionicHacktool.Win32.Black.3!c
MicroWorld-eScanTrojan.Generic.21484974
McAfeeArtemis!30BE40B48DD6
MalwarebytesMalware.AI.4224248792
SangforTrojan.Win32.Ymacco.Vrmc
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.Generic.21484974
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.36250.JS0aaGZzYrnb
VirITPacked.Win32.Black.D
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Black.d
AlibabaPacked:Win32/Black.4b465cf0
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11558534
EmsisoftTrojan.Generic.21484974 (B)
VIPRETrojan.Generic.21484974
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeTrojan.Generic.21484974
SophosMal/Generic-S
GDataTrojan.Generic.21484974
JiangminPacked.Black.altf
ArcabitTrojan.Generic.D147D5AE
ZoneAlarmPacked.Win32.Black.d
MicrosoftTrojan:Win32/Ymacco.AA62
VBA32BScope.Trojan.Ymacco
ALYacTrojan.Generic.21484974
MAXmalware (ai score=97)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CD323
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
AVGWin32:Malware-gen
Cybereasonmalicious.48dd6b
DeepInstinctMALICIOUS

How to remove Malware.AI.4224248792?

Malware.AI.4224248792 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment