Malware

Malware.AI.4254158655 removal guide

Malware Removal

The Malware.AI.4254158655 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4254158655 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Anomalous binary characteristics

How to determine Malware.AI.4254158655?


File Info:

name: 4A0F29E86344710E351C.mlw
path: /opt/CAPEv2/storage/binaries/c0be58e80df9825aa5d6b30ff2316c00df832b2292f501bc808444af1e134cb9
crc32: AD2A4B94
md5: 4a0f29e86344710e351cca2349e99841
sha1: deb45a54b5946644d08d5c683d855cbe497133e5
sha256: c0be58e80df9825aa5d6b30ff2316c00df832b2292f501bc808444af1e134cb9
sha512: 58beed1df39a1f6bfe3e1124c03be96079976a4234e515686027bfef8c2a45671e3549288a8422acabb39908caa16a61265405b92f902bc41b66b5c73276362a
ssdeep: 49152:IETB/QvQ9zwzgvlKpci6rBmiUthKrxJ8Cm/6ChVbm6Gox6BG/0qwTQ79kiC4:IEd99zwUl6TsTUtyJ7qDbmXoH0qwT+fZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5F533F89E0B3246D2E090B1C8D3223A6CD4AD72FFF8D31E4CD8456585B4A217979B97
sha3_384: 19eb2649dc6d1b1e097ec81f01b0641e952ba34df573b6905d489e940c183af80e2f546e5209b9b167f4243188ce41c1
ep_bytes: 60be00e0e1008dbe00305eff5789e58d
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: JFX
ProductName: WinNTSetup
ProductVersion: 5.2.0.0
FileVersion: 5.2.0.0
FileDescription: Universal Windows Installer
OriginalFilename: WinNTSetup_x86.exe
LegalCopyright: JFX
Build date: 2022/02/03
Translation: 0x0409 0x04b0

Malware.AI.4254158655 also known as:

CylanceUnsafe
APEXMalicious
ClamAVWin.Malware.Johnnie-6858836-0
DrWebTrojan.MulDrop8.53089
FireEyeGeneric.mg.4a0f29e86344710e
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Qhost.it
Antiy-AVLTrojan/Generic.ASMalwS.2898FB6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.4254158655
YandexTrojan.GenAsa!hJ6mFcs89Bg
BitDefenderThetaGen:NN.ZelphiF.34182.upNfaeaKNali

How to remove Malware.AI.4254158655?

Malware.AI.4254158655 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment