Malware

Malware.AI.4250559138 removal guide

Malware Removal

The Malware.AI.4250559138 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4250559138 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Malware.AI.4250559138?


File Info:

name: F115FBEA919204F6F23C.mlw
path: /opt/CAPEv2/storage/binaries/736b5c8ecbbd6f2f1b9f59eefbdc58cfa438487201cfdf7867a9baa9568d837c
crc32: 92324CBD
md5: f115fbea919204f6f23cbfa48f0d1009
sha1: 215b17fc49ea7cafeb25b2884124b2a3e5ebb53c
sha256: 736b5c8ecbbd6f2f1b9f59eefbdc58cfa438487201cfdf7867a9baa9568d837c
sha512: d7eed513cc6612a0f2279b227eaf2253223dbe27e5e2d85e7b8a97027a59583baa02796c9473463df3c6664d24b742ccdb085fd27eaefd80a8c156bc9c45bbfe
ssdeep: 24576:ACdxte/80jYLT3U1jfsWa6Se3bhIKVNuHNJgrUOARUSW3mQ:pw80cTsjkWa6BrBq8rtnSWB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10985AED263FDC660C6A65172FA1FE3F13E6AFC630520B45B2EC43D6BB930165112C66A
sha3_384: 3ce1e001f432374d4dc8d6bce2efa9d3dc4b1cd052ba33fe3bbe17e3ea8d7be027a46981a2a4fcd6f9704075571b2393
ep_bytes: e8b8d00000e97ffeffffcccccccccccc
timestamp: 2019-10-24 10:11:43

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.4250559138 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!e
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.660
McAfeeArtemis!F115FBEA9192
CylanceUnsafe
VIPREAIT:Trojan.Nymeria.660
SangforTrojan.Win32.Occamy.C73
BitDefenderAIT:Trojan.Nymeria.660
APEXMalicious
Paloaltogeneric.ml
Ad-AwareAIT:Trojan.Nymeria.660
EmsisoftAIT:Trojan.Nymeria.660 (B)
ComodoMalware@#25ktc3mumh2iq
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
FireEyeAIT:Trojan.Nymeria.660
GDataAIT:Trojan.Nymeria.660 (2x)
WebrootW32.Trojan.Nymeria
ArcabitAIT:Trojan.Nymeria.660
MicrosoftTrojan:Win32/Occamy.C73
AhnLab-V3Trojan/Win32.Azden.C3565010
ALYacAIT:Trojan.Nymeria.660
MAXmalware (ai score=99)
MalwarebytesMalware.AI.4250559138
TrendMicro-HouseCallTROJ_GEN.R002H09EJ21
MaxSecureTrojan.Malware.74482801.susgen
BitDefenderThetaAI:Packer.3AFFCAD816

How to remove Malware.AI.4250559138?

Malware.AI.4250559138 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment