Malware

Should I remove “Malware.AI.4250276310”?

Malware Removal

The Malware.AI.4250276310 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4250276310 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Starts servers listening on 127.0.0.1:0
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Malware.AI.4250276310?


File Info:

name: 691B868479831DB90DD8.mlw
path: /opt/CAPEv2/storage/binaries/2ea8d97a7f7bf98402f85c6d4598093fc3f0d32a2d7170e535fff626d09c2c88
crc32: 552FC658
md5: 691b868479831db90dd89c01dfd44ee9
sha1: b22e4cd3e720116f59e7f6b60f0349552d2bd960
sha256: 2ea8d97a7f7bf98402f85c6d4598093fc3f0d32a2d7170e535fff626d09c2c88
sha512: 49de3ecd9a28379717fc7792b9cd628b7870c7efafcf94f143a1d0dbbd23b37f856b51aa6287b1bc5737861733af0feecd6f5a81bbea3456b5093f514fe95bb6
ssdeep: 12288:KaOHJRpM0bRm6hqcD6fmzCewgFUchWEaZScDOeWGHIeJLgr35yz14odctgOwP2:KaOXpMSq27zCewKUchWEm1H18r35Yxsg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DD4B05279C1C0B1D2B2213455BD9B774D3EAB261B11BBD7E3D00A794E201E0AE3A77E
sha3_384: adffa33cf8772b8a09049b18c74bb5967431cde3540f591cc17e7fe97507ae596d5142a9365ec605a098769b17124436
ep_bytes: e82e060000e974feffff8b4df464890d
timestamp: 2022-05-05 16:48:42

Version Info:

0: [No Data]

Malware.AI.4250276310 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.87040
FireEyeGeneric.mg.691b868479831db9
McAfeeArtemis!691B86847983
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0046904a1 )
AlibabaTrojanDownloader:Win32/Generic.f58e0d80
K7GWTrojan ( 0046904a1 )
Cybereasonmalicious.3e7201
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.VBX
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
BitDefenderGen:Variant.Fragtor.87040
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11f828af
Ad-AwareGen:Variant.Fragtor.87040
EmsisoftGen:Variant.Fragtor.87040 (B)
F-SecureTrojan.TR/Agent.zxkxe
VIPREGen:Variant.Fragtor.87040
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Agent.zxkxe
MAXmalware (ai score=82)
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Fragtor.D15400
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
GDataGen:Variant.Fragtor.87040
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C5177057
VBA32BScope.TrojanDownloader.Agent
ALYacGen:Variant.Fragtor.87040
MalwarebytesMalware.AI.4250276310
TrendMicro-HouseCallTROJ_GEN.R002H0CFU22
RisingDownloader.Agent!8.B23 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34742.MyW@aSq3jLji
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.4250276310?

Malware.AI.4250276310 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment