Malware

Malware.AI.4249187144 removal instruction

Malware Removal

The Malware.AI.4249187144 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4249187144 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity

How to determine Malware.AI.4249187144?


File Info:

name: A25E21335B1EFC089A5D.mlw
path: /opt/CAPEv2/storage/binaries/d824941a5bac7a9feb2bb1579601ae079c33b50194022f2da43f62b14951e0a1
crc32: DFFFAAEB
md5: a25e21335b1efc089a5da326e44b7182
sha1: 0f85591c7ee42423a46c33e9471463e484a49c53
sha256: d824941a5bac7a9feb2bb1579601ae079c33b50194022f2da43f62b14951e0a1
sha512: 70d28c575947fbedf66b5b81b16f42a1eb45d9fc2aed5e0a6ed938101b20a439cb6e3ad2fa9a3274d3133059cab5e2ce063dd24f1b797eb78367427144c09b1a
ssdeep: 98304:iobLpveqkpeNWb3Jn0wPXvTn5KvCmBqMAwiEBRf2DJh6nYHm4ooSf2tZ/5XgxTvM:ioPNeqkpmWb50w3T5cBJghVYf2rh6esM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13236DE4E4C01A534DEC0CCB093D2A6F5ED477C1303726686BF46BA9939F5EB15983A2E
sha3_384: 2ce8a233187c96923fc9e607c8a38e3de135193895a92ca5987fef19a6c38754379ba847162e47999f1408443faf1ff6
ep_bytes: 60be004049008dbe00d0f6ff5783cdff
timestamp: 2021-11-25 16:20:54

Version Info:

FileVersion: 1.0.0.0
FileDescription: 360软件管家
ProductName: 360软件管家
ProductVersion: 1.0.0.0
CompanyName: 360软件管家
LegalCopyright: 360软件管家
Comments: 360软件管家
Translation: 0x0804 0x04b0

Malware.AI.4249187144 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a25e21335b1efc08
CAT-QuickHealTrojan.Generic.2919
McAfeeGenericRXAA-AA!A25E21335B1E
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1639445
SangforTrojan.Win32.Save.a
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Steam.NGA
APEXMalicious
ClamAVWin.Malware.Vmprotect-6824127-0
KasperskyUDS:Trojan.Win32.Generic
AvastWin32:TrojanX-gen [Trj]
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.BtcMine.1317
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.5LSHNI
JiangminTrojan.Generic.heinq
AviraTR/PSW.Steam.besws
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win32.Generic.C4208472
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34114.@pKfa8tV3mab
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.4249187144
RisingStealer.Agent!1.D531 (RDMK:cmRtazqLTQDivdOITbhbNPOIVt0u)
IkarusTrojan.Win32.FlyAgent
FortinetW32/CoinMiner.ELG!tr.pws
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c7ee42
PandaTrj/GdSda.A

How to remove Malware.AI.4249187144?

Malware.AI.4249187144 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment