Malware

How to remove “Malware.AI.4243887388”?

Malware Removal

The Malware.AI.4243887388 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4243887388 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.4243887388?


File Info:

name: 21C9EED9765E98B18516.mlw
path: /opt/CAPEv2/storage/binaries/f598f6d15a229f47ab7a8120718d817a62b98add0c3ce76298266b57dfdcbe9c
crc32: 68A0D99C
md5: 21c9eed9765e98b185169ecc06b838db
sha1: d121b67a8642e13d76785552b2bfdaf7eab5ac35
sha256: f598f6d15a229f47ab7a8120718d817a62b98add0c3ce76298266b57dfdcbe9c
sha512: cb9e50d70f8e61e62a6441511b11c6b4ae6bd19908b418a1d2db87e82b4ed3e15cc4afe1003a48b88a7f0045c18d32425e973e892bd340cf01a98ad0ee693390
ssdeep: 12288:HqvMKYWBlswFR02ikQEA6guwagmwaAegaAGAaAuQaAmQ6g+gaggDiBD:wWwFRB5QEA6guwagmwaAegaAGAaAuQaE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175B4B63E65169EE3D96C71F342A9486943750C972320CEB678F1B1B599B1B73CE0222F
sha3_384: 3c07193a1793d67b35762fd409c94c2870b54fd01e07b30f6a1c5dba1e8fd9d57901bfe8e61956991141be0b6e0e1460
ep_bytes: ff250020400000000000000000000000
timestamp: 2057-01-03 19:40:05

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: PROXY
FileVersion: 1.0.0.0
InternalName: PROXY.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: PROXY.exe
ProductName: PROXY
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4243887388 also known as:

LionicTrojan.MSIL.Stealer.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48334606
ALYacTrojan.GenericKD.48334606
CylanceUnsafe
SangforInfostealer.MSIL.Stealer.gen
K7AntiVirusRiskware ( 0055ead31 )
BitDefenderTrojan.GenericKD.48334606
K7GWRiskware ( 0055ead31 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Trojan.CIMC-0630
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Riskware.HackTool.Agent.BT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:xr+OmX25SWPtCBizcVaNjg)
Ad-AwareTrojan.GenericKD.48334606
SophosMal/Generic-S
DrWebTrojan.PWS.Siggen3.11377
TrendMicroTROJ_GEN.R032C0WBI22
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.21c9eed9765e98b1
EmsisoftTrojan.GenericKD.48334606 (B)
IkarusTrojan.MSIL.Vmprotect
Antiy-AVLTrojan/Generic.ASMalwS.352CC72
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.48334606
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4973309
McAfeeArtemis!21C9EED9765E
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.4243887388
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R032C0WBI22
YandexRiskware.HackTool!r0L+KwB7Ctg
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat.PALLAS.H
BitDefenderThetaGen:NN.ZemsilF.34232.Gm0@a8oJ!v
AVGWin32:Malware-gen
Cybereasonmalicious.a8642e
AvastWin32:Malware-gen

How to remove Malware.AI.4243887388?

Malware.AI.4243887388 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment