Malware

Should I remove “Malware.AI.4251957842”?

Malware Removal

The Malware.AI.4251957842 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4251957842 virus can do?

  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script or command line contains a long continuous string indicative of obfuscation
  • Deletes executed files from disk
  • Attempts to execute suspicious powershell command arguments

How to determine Malware.AI.4251957842?


File Info:

name: 392C58273FD1D47BE518.mlw
path: /opt/CAPEv2/storage/binaries/844688166436d5796e85e71c3548244d7ec88d32e512aff75743f619a6e53626
crc32: A76BCCFA
md5: 392c58273fd1d47be5183d7fbcdb238b
sha1: 8bc8913ea8bd044a6bd37d00d7ce169c6a17f2f1
sha256: 844688166436d5796e85e71c3548244d7ec88d32e512aff75743f619a6e53626
sha512: fb18a659b75d23e73ae5a065697b26c36e35beddd7f9fb10fa9e0f1334e1ea51e9f8e986599ef7422a9afa0019e49bd5cf16594470b8158f22e6b8047996cbe4
ssdeep: 3072:k7DhdC6kzWypvaQ0FxyNTBfAdja3r5MA0L5veDfOf0tPj8doc5SJPuc:kBlkZvaF4NTBYYv0LAA0r8tOJ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11844D041B2E041F7D9F1093104A6B22E923E6F399F60A4D7CB4C3A4669736D4DA3D3E9
sha3_384: ca82f27bfdc6df25ef62bc14d1c7168d37cb8e32aad15fdd44f496698b03350701577d6d6379081c54a9f17e81e735d9
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

FileVersion: 1.1
ProductVersion: 1.1
ProductName: McGEN
OriginalFilename: McGEN
InternalName: McGEN
FileDescription: Program to find minecraft passwords!
CompanyName: NeonGriefers
LegalTrademarks: NeonGriefers
LegalCopyright: NeonGriefers
PrivateBuild: NeonGriefers
SpecialBuild: NeonGriefers
Translation: 0x0000 0x04e4

Malware.AI.4251957842 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Encoder.trrL
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.392c58273fd1d47b
CAT-QuickHealTrojan.GenericPMF.S16976269
McAfeeArtemis!392C58273FD1
CylanceUnsafe
VIPREGen:Trojan.FileInfector.qu0@a0qe5ij
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Trojan.FileInfector.qu0@a0qe5ij
MicroWorld-eScanGen:Trojan.FileInfector.qu0@a0qe5ij
AvastWin32:Malware-gen
Ad-AwareGen:Trojan.FileInfector.qu0@a0qe5ij
EmsisoftGen:Trojan.FileInfector.qu0@a0qe5ij (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.FileInfector.qu0@a0qe5ij
Antiy-AVLTrojan/Generic.ASMalwS.5174
ArcabitTrojan.FileInfector.ED1ED6E
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.C5230184
ALYacGen:Trojan.FileInfector.qu0@a0qe5ij
MAXmalware (ai score=83)
MalwarebytesMalware.AI.4251957842
TrendMicro-HouseCallTROJ_GEN.R002H09HU22
RisingTrojan.Generic@AI.96 (RDML:fO+3PpV3r3ocqt5R2G2HPQ)
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34606.qu0@a0qe5ij
AVGWin32:Malware-gen

How to remove Malware.AI.4251957842?

Malware.AI.4251957842 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment