Malware

Malware.AI.4241296393 removal instruction

Malware Removal

The Malware.AI.4241296393 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4241296393 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Malware.AI.4241296393?


File Info:

name: CC2A4F463539B9BAC0EE.mlw
path: /opt/CAPEv2/storage/binaries/5b2aaf907d381d79113a93c07fee81136c9a92f80a6e0f9fe131885ede71cac7
crc32: ADFE85AB
md5: cc2a4f463539b9bac0eeb2146287b212
sha1: 79753aefa40e4fd3defdb19f5f16059b7c05dad2
sha256: 5b2aaf907d381d79113a93c07fee81136c9a92f80a6e0f9fe131885ede71cac7
sha512: 82f29886268e7f86453b702e65a612095318be45415bce2be5dabc5abacf5736fd7e60de22ebdb7081c13ff6357c91da3d5f6f66cc27cf1551ffd033ee6320b6
ssdeep: 49152:pOp6jL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4AjL4m:pOp6jbbbbbbbbbbbbbbbbbUH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A261247B0099712C9492B7356C3F7B823B6B65265BBD31A2F7CBB884885FBF4411836
sha3_384: 2f0c906323e31493e04c9c588ce8d0e08993ab4d77c65597f7aa916f5c59e633c6e47d3aaa481aff3a20bed8e8064bf4
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-12-29 21:01:48

Version Info:

Translation: 0x0000 0x04b0
FileDescription: DOLYAN SPOM
FileVersion: 1.0.0.0
InternalName: DOLYAN SPOM.exe
LegalCopyright: Copyright © 2020
OriginalFilename: DOLYAN SPOM.exe
ProductName: DOLYAN SPOM
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4241296393 also known as:

LionicTrojan.MSIL.Bladabindi.m!c
MicroWorld-eScanGen:Variant.Razy.821136
FireEyeGeneric.mg.cc2a4f463539b9ba
ALYacGen:Variant.Razy.821136
CylanceUnsafe
ZillyaBackdoor.Bladabindi.Win32.22943
SangforTrojan.MSIL.Kryptik.ZDF
K7AntiVirusTrojan ( 005756221 )
AlibabaBackdoor:MSIL/Bladabindi.b18a9555
K7GWTrojan ( 005756221 )
Cybereasonmalicious.63539b
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.ZDF
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Razy.821136
NANO-AntivirusTrojan.Win32.Bladabindi.joxcla
AvastWin32:Trojan-gen
TencentMsil.Backdoor.Bladabindi.Gajl
Ad-AwareGen:Variant.Razy.821136
SophosGeneric ML PUA (PUA)
ComodoMalware@#2dni60glve8nd
DrWebBackDoor.Bladabindi.16104
VIPREGen:Variant.Razy.821136
TrendMicroBackdoor.MSIL.BLADABINDI.USXVPX
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Razy.821136 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.821136
AviraHEUR/AGEN.1236518
Antiy-AVLTrojan/Generic.ASMalwS.3E3F
KingsoftWin32.Hack.Undef.(kcloud)
ArcabitTrojan.Razy.DC8790
MicrosoftBackdoor:MSIL/Bladabindi
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.C4225836
Acronissuspicious
McAfeeArtemis!CC2A4F463539
MAXmalware (ai score=84)
MalwarebytesMalware.AI.4241296393
TrendMicro-HouseCallBackdoor.MSIL.BLADABINDI.USXVPX
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:QRPD2T0uwmhAcNNekv83Ow)
YandexTrojan.Kryptik!yv34s0n9tNI
IkarusGen.MSIL.Bladabindi
MaxSecureTrojan.Malware.73686729.susgen
FortinetMSIL/Kryptik.YZW!tr
BitDefenderThetaGen:NN.ZemsilF.34646.@p0@aKSthu
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4241296393?

Malware.AI.4241296393 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment