Malware

Should I remove “Malware.AI.4252240790”?

Malware Removal

The Malware.AI.4252240790 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4252240790 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.4252240790?


File Info:

name: 949880F92D75221E073A.mlw
path: /opt/CAPEv2/storage/binaries/04f41cc6e1dd74fcba37759cbd76c57c5ca2687fb8a8263bc5e575b3f1114b08
crc32: F299AD90
md5: 949880f92d75221e073aa94510abecdf
sha1: 284f048b1c51479745cfeb98adcc2b66eaf4fafc
sha256: 04f41cc6e1dd74fcba37759cbd76c57c5ca2687fb8a8263bc5e575b3f1114b08
sha512: 3f60bfcbe76d9a24cd3c78703fdd7d8b0facd5bb9fae5d2bab40924c52667cd28e59025cc67ddd9f9ac030d857c633c481ad472419b8081a1da5d0cb25de4ba7
ssdeep: 24576:43MjgwAe0O0W8SQh+TyktREJjw3H2MRQC946Bb92YNps:43MjgwA3O0WBQhTJjw3H2MRQr89lps
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16945DF10FBAFE4F0E8470E71844E633FA7765208583DEE16FB887D27E9339225919256
sha3_384: 5dfa24bc0c01207dce239df9fc33bac2a97f2181b1f4f1cadc917629c0be8b89b4d40cfdd0e1782eb59dbc8f357172b6
ep_bytes: 5589e583ec08c7042402000000ff1544
timestamp: 2014-03-15 19:52:20

Version Info:

0: [No Data]

Malware.AI.4252240790 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.DealPly.4!c
SangforTrojan.Win32.Agent.Vxyr
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
IkarusPUA.DealPly
WebrootW32.Adware.Gen
Antiy-AVLGrayWare/Win32.Presenoker
ViRobotAdware.Presenoker.1223796
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DealPly.R271409
DeepInstinctMALICIOUS
MalwarebytesMalware.AI.4252240790
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Malware.AI.4252240790?

Malware.AI.4252240790 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment