Malware

What is “Malware.AI.4233694215”?

Malware Removal

The Malware.AI.4233694215 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4233694215 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • A script process created a new process
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

How to determine Malware.AI.4233694215?


File Info:

name: B1ADF278BA7DADEE8F37.mlw
path: /opt/CAPEv2/storage/binaries/58eaa7042ec4879f8fab20acd96c75c0d0d085f0f82e229bbd337cca00477832
crc32: 7132992F
md5: b1adf278ba7dadee8f37854973612557
sha1: 380520ef19fa2f1f4814c1c5099879a77107d79d
sha256: 58eaa7042ec4879f8fab20acd96c75c0d0d085f0f82e229bbd337cca00477832
sha512: 5c81f8f37f35501df192d5f77b4084266ad07a1de8da4f0f0d131c2d9af53d76cc48bc91bf7938db243d2da15d7d292f4d7c2d54523f6c34ec96afaddebaeaa3
ssdeep: 49152:aVg5tQ7am8oVNkmIaLZArEl+0XNxKnY5:Eg56cFk+i7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16F95CE2A37FEF334F2E1A133EE51B6116D7B6C1E1D60B1962E443A387CE1961420E5B6
sha3_384: 3af913b992990b72f61ae9382b909d12f8d78465a5850ba7b487fc3236af2ef0faf07ca94f881e06cc58acb7dfbff7d0
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2016-10-23 02:52:00

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.4233694215 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.4040310
FireEyeGeneric.mg.b1adf278ba7dadee
McAfeeArtemis!B1ADF278BA7D
MalwarebytesMalware.AI.4233694215
K7AntiVirusTrojan ( 005642691 )
AlibabaBackdoor:Win32/Androm.11ad28fe
K7GWTrojan ( 005642691 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaAI:Packer.4F40BF1215
ESET-NOD32a variant of Win32/Injector.Autoit.BNW
TrendMicro-HouseCallTROJ_GEN.R002H0CKS21
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.mbky
BitDefenderTrojan.GenericKD.4040310
NANO-AntivirusTrojan.Win32.Androm.ekeqsa
AvastWin32:Trojan-gen
TencentWin32.Backdoor.Androm.Pepp
Ad-AwareTrojan.GenericKD.4040310
EmsisoftTrojan.GenericKD.4040310 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosML/PE-A
IkarusTrojan.Win32.Injector
AviraHEUR/AGEN.1100158
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.4040310
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.4040310
APEXMalicious
eGambitUnsafe.AI_Score_78%
FortinetW32/Autoit.BNW!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.4233694215?

Malware.AI.4233694215 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment