Malware

Malware.AI.4250864100 removal

Malware Removal

The Malware.AI.4250864100 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4250864100 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Likely installs a bootkit via raw harddisk modifications
  • Wrote 512 bytes to physical drive potentially indicative of overwriting the Master Boot Record (MBR)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempted to write directly to a physical drive
  • Deletes executed files from disk
  • Harvests cookies for information gathering

How to determine Malware.AI.4250864100?


File Info:

name: E30AD32495D805A14587.mlw
path: /opt/CAPEv2/storage/binaries/1b5c61097380572a2c1cf9f2d7d3eab8ac6b23d03657d5e04dd568dee5b2aaed
crc32: 7A8257B2
md5: e30ad32495d805a1458794a8e0aafc24
sha1: 41b32ac850be1d6ceb07f7a78af39843e4ffdc22
sha256: 1b5c61097380572a2c1cf9f2d7d3eab8ac6b23d03657d5e04dd568dee5b2aaed
sha512: 9a70b3c94c0ee45c1469510d58e2dc36d3dd4126dc4a88555e5fbf6c10ecb5b5c44c0d231ea9e3cab539230216c3f37bb24bc66206d987a2add5155996aa7e93
ssdeep: 1536:vO/rn8gU/M3p1thokZGqKTRSpEvMfC6+iLPLvXta0PTEzh:jdwhURSpUMfCvirLPta0bEd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15DC34B8134A8C171FC65113640D6DE3B963DA8B2272542C3BAD839CD8D92FCB5B7A6C7
sha3_384: e92fc824aa4affa4a4288140a2656844ece266f3fd7fd4f681bce15d1b51113725d4e4d4d05bad3ea741138e55afe168
ep_bytes: e87e520000e916feffff558bec81ec28
timestamp: 2015-10-24 18:19:30

Version Info:

0: [No Data]

Malware.AI.4250864100 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.KillFiles.30756
FireEyeGeneric.mg.e30ad32495d805a1
MalwarebytesMalware.AI.4250864100
K7AntiVirusTrojan ( 004d672c1 )
K7GWTrojan ( 004d672c1 )
VirITTrojan.Win32.KillFiles.BTMY
ESET-NOD32a variant of Win32/KillDisk.NBC
ClamAVWin.Trojan.Mikey-9958102-0
KasperskyTrojan.Win32.KillDisk.ft
NANO-AntivirusTrojan.Win32.KillFiles.dypoav
AvastWin32:KillDisk-U [Trj]
SophosTroj/Defkill-A
IkarusTrojan.Win32.Swisyn
JiangminTrojan.Generic.fcwy
Antiy-AVLTrojan/Generic.ASMalwS.3303
ViRobotTrojan.Win32.Agent.110592.DV
ZoneAlarmTrojan.Win32.KillDisk.ft
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1267761
VBA32Trojan.KillDisk
CylanceUnsafe
APEXMalicious
RisingTrojan.[Sandworm]KillDisk!1.A38A (CLASSIC)
YandexTrojan.KillDisk!yrD+sjDsWzU
AVGWin32:KillDisk-U [Trj]
Cybereasonmalicious.850be1
PandaTrj/GdSda.A

How to remove Malware.AI.4250864100?

Malware.AI.4250864100 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment