Malware

Malware.AI.4225062375 removal tips

Malware Removal

The Malware.AI.4225062375 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4225062375 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the DarkComet malware family
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4225062375?


File Info:

name: C20814541DF5482FB526.mlw
path: /opt/CAPEv2/storage/binaries/cc79d57902f6d7fc8294ab276851ced63e399064a09ab86384fa02b0abbe1f92
crc32: FA246ECC
md5: c20814541df5482fb526b7f4ffa3a29a
sha1: b336b3ac8bd26d1408958a93d6186f1fe92cd34f
sha256: cc79d57902f6d7fc8294ab276851ced63e399064a09ab86384fa02b0abbe1f92
sha512: 35b3924a75cf13f4b90d140d84ee3dcee135195727c4ae788f67aefc8b0393c9d8a8fdcd77d02bc42fa8a21e21a6f64c0799e2a0d2b4511a80936d9a58ec102d
ssdeep: 12288:CXRZxdlXlv3TlG2KoEgy1I9ZZdFKLvNx8PWX9SROeOxzf/q3ltresW5z5S:sRrDBEtocCZdErNGeQRdAK/Ks
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C15AF33B6808877D9730D388C6B92A5947A7E202D39B54B3AE57F4D6F392C239152C7
sha3_384: 48c2b8fac21e7525c553bb13dffe396f00fdced6be593671a75b3fcc679bf7e1398ca2b6554c2d9835ea1533c2fa62c7
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-02-17 21:20:38

Version Info:

Translation: 0x0000 0x04b0
Comments: This project was made by SuperCell Community
CompanyName: SuperCell
FileDescription: Clash Of Clans Gem Miner - PRE Release
FileVersion: 3721.2163.7339.8559
InternalName: Clash Of Clans Gem Miner - PRE Release.exe
LegalCopyright: SuperCell
LegalTrademarks: SuperCell
OriginalFilename: Clash Of Clans Gem Miner - PRE Release.exe
ProductName: Gem Miner
ProductVersion: 3721.2163.7339.8559
Assembly Version: 8159.7347.4093.761

Malware.AI.4225062375 also known as:

LionicTrojan.Win32.DarkKomet.m!c
tehtrisGeneric.Malware
DrWebTrojan.KeyLogger.26163
MicroWorld-eScanTrojan.MSIL.Basic.7.Gen
FireEyeGeneric.mg.c20814541df5482f
McAfeeArtemis!C20814541DF5
MalwarebytesMalware.AI.4225062375
ZillyaBackdoor.DarkKomet.Win32.28420
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/DarkKomet.2b12c2cb
Cybereasonmalicious.41df54
BitDefenderThetaGen:NN.ZemsilF.36662.3m0@aaITOToG
VirITTrojan.Win32.MSIL7.ASS
CyrenW32/MSIL_Agent.GHC.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.HXC
APEXMalicious
KasperskyBackdoor.Win32.DarkKomet.evcy
BitDefenderTrojan.MSIL.Basic.7.Gen
NANO-AntivirusTrojan.Win32.DarkKomet.doagox
AvastWin32:Malware-gen
TencentWin32.Backdoor.Darkkomet.Lcnw
EmsisoftTrojan.MSIL.Basic.7.Gen (B)
F-SecureHeuristic.HEUR/AGEN.1308628
VIPRETrojan.MSIL.Basic.7.Gen
TrendMicroTROJ_GEN.R002C0GHO23
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.MSIL.Basic.7.Gen
JiangminBackdoor/DarkKomet.ijl
WebrootW32.Gen.BT
GoogleDetected
AviraHEUR/AGEN.1308628
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet
XcitiumMalware@#17mgyj1toka25
ArcabitTrojan.MSIL.Basic.7.Gen
ZoneAlarmBackdoor.Win32.DarkKomet.evcy
MicrosoftVirTool:Win32/DelfInject.gen!BI
CynetMalicious (score: 99)
VBA32TScope.Trojan.MSIL
ALYacTrojan.MSIL.Basic.7.Gen
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0GHO23
RisingBackdoor.Darkcomet!8.1117F (CLOUD)
YandexBackdoor.DarkKomet!loXKq69EdE0
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.8401360.susgen
FortinetMSIL/Injector.HZL!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4225062375?

Malware.AI.4225062375 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment