Malware

About “Malware.AI.4252235168” infection

Malware Removal

The Malware.AI.4252235168 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4252235168 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.4252235168?


File Info:

name: 649EB237000C2300F979.mlw
path: /opt/CAPEv2/storage/binaries/8bbd5dc407cff421fd350416cfd5fa21299fa1e3fc1993b270749e06bc7a1dfe
crc32: D4E9FA88
md5: 649eb237000c2300f9793a113feffa21
sha1: 2b93e81b95276fbdef1842deacf42e96f623b036
sha256: 8bbd5dc407cff421fd350416cfd5fa21299fa1e3fc1993b270749e06bc7a1dfe
sha512: 1f2a4454df8b6bd8f295bf9f6f0d923bcad1a3adbe76711bfcedb9b133671a2f3d3114953c842956680198a08cbaa666c090b628db9df161f06fd4dfc36694a5
ssdeep: 98304:9BTbkptzJbs8j5Nw6BaUCc16/UI855WYGR7o16lqLxjX:9yrz1s81NhBFCc11I8aj7nqLxj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182F5334377E341B4F2A06D38CD299140AE3338B909E474A92CF8C74F6DB56C29DB6B59
sha3_384: 8bafdeb85c6602fad0fee51671521c59f7b2d3a892441b10df993306b5ce686a5dab9c6c2ca8c6b0f18546a0a807c40d
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2016-04-06 14:39:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: AceTools.biz
FileDescription: Ace Translator 16 Installer
FileVersion: 16
LegalCopyright: Copyright © 2016 AceTools.biz
ProductName: Ace Translator
ProductVersion: 16
Translation: 0x0000 0x04b0

Malware.AI.4252235168 also known as:

LionicTrojan.Win32.Stealer.12!c
SkyhighBehavesLike.Win32.Dropper.wc
MalwarebytesMalware.AI.4252235168
K7AntiVirusPassword-Stealer ( 004e03421 )
AlibabaTrojan:Win32/DataStealer.0b32b3df
K7GWPassword-Stealer ( 004e03421 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/AceTools.A
TrendMicro-HouseCallTROJ_GEN.R002C0DKM23
McAfeeArtemis!649EB237000C
NANO-AntivirusTrojan.Win32.Stealer.efalzl
AvastWin32:Malware-gen
TencentWin32.Trojan.Redcap.Udkl
F-SecureTrojan.TR/Redcap.qpbtq
DrWebTrojan.PWS.Stealer.18079
TrendMicroTROJ_GEN.R002C0DKM23
SophosMal/Generic-S
IkarusPUA.Avanquest
AviraTR/Redcap.qpbtq
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.755
MicrosoftTrojan:Win32/Malgent!MSR
XcitiumMalware@#3s8x5fjpz1x7w
MAXmalware (ai score=99)
VBA32TrojanPSW.Stealer
Cylanceunsafe
RisingTrojan.DataStealer!8.77B (TFE:5:Ru3kksWv5jG)
YandexTrojan.GenAsa!Y3jzr5lkXTs
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/DataStealer.P!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/AceTools.A

How to remove Malware.AI.4252235168?

Malware.AI.4252235168 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment