Malware

Malware.AI.4241919431 removal instruction

Malware Removal

The Malware.AI.4241919431 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4241919431 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.4241919431?


File Info:

name: 1C43F8317E40D2703CAD.mlw
path: /opt/CAPEv2/storage/binaries/82c03332b51cb7bee7872a8018c6235e58b71053cab2de20cd06da4072cb2096
crc32: 8C912E13
md5: 1c43f8317e40d2703cadb8f6126b281f
sha1: 7c7fa6cf43d611661a280bab6cd615e43e6d01bd
sha256: 82c03332b51cb7bee7872a8018c6235e58b71053cab2de20cd06da4072cb2096
sha512: 4a68a04f1f9d8e19b11056ffa0e31acb7c0d5f89d74bbfbd2b4e39edea291c50f522ca634abf75c306deb8f36eccc65dc69c99f7e342df63d4de7c202d5963ef
ssdeep: 49152:8C9dvL5A+2sjnzBFrnrtXAAfSo6n8Hx0FXjYyQEP2UbJVY5GPJ:3F2sjzBxnr2AfFs8AzYyQ63zAGPJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBB53331056F110FF91228BC6A9F1226512BEC135ECD43B69D19BB86DCB34F892D2D6B
sha3_384: 7d954e78124261847787f2eac465a3d8a4ad227bae5ab2a875b54abd3043c2cf72c4e8f7e8a3f2a6b5510aa620021504
ep_bytes: 60be001080008dbe0000c0ff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Chengdu Kungho Technology Co,. Ltd.
FileDescription: 网升安全中心
FileVersion: 1.2.1.445
InternalName:
LegalCopyright: Copyright by Kungho Technology
LegalTrademarks:
OriginalFilename: KHCore.exe
ProductName: 网升安全中心
ProductVersion: 1.0.0.0
Comments: 全功能版
Translation: 0x0804 0x03a8

Malware.AI.4241919431 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Jaik.61797
FireEyeGeneric.mg.1c43f8317e40d270
McAfeeGenericRXBB-YE!55E2BC30E374
MalwarebytesMalware.AI.4241919431
BitDefenderGen:Variant.Jaik.61797
Cybereasonmalicious.17e40d
BitDefenderThetaAI:Packer.7945ECEB17
CyrenW32/OnlineGames.CE.gen!Eldorado
SymantecML.Attribute.HighConfidence
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Generic@AI.84 (RDMK:cmRtazpePlt3mfyzSAKrcktFr79r)
Ad-AwareGen:Variant.Jaik.61797
VIPREGen:Variant.Jaik.61797
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Jaik.61797 (B)
APEXMalicious
AviraHEUR/AGEN.1232575
Antiy-AVLTrojan/Generic.ASMalwS.5406
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Jaik.61797
AhnLab-V3Malware/Win.Generic.R447710
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Jaik.61797
MAXmalware (ai score=89)
CylanceUnsafe
YandexTrojan.GenAsa!CC9nLRXlbw4
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware [Trj]
AvastFileRepMalware [Trj]

How to remove Malware.AI.4241919431?

Malware.AI.4241919431 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment