Malware

Malware.AI.4254228677 removal guide

Malware Removal

The Malware.AI.4254228677 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4254228677 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4254228677?


File Info:

name: 5A577C3E8AF9E80F8611.mlw
path: /opt/CAPEv2/storage/binaries/562e0a64bddc1cea144894f793dac6806d2a8d252f3ddfff95d0d5d844eeafea
crc32: 14D73386
md5: 5a577c3e8af9e80f8611f08d5b4daafb
sha1: b60ffb66757dcfdb43bdf5cd267d57fed2998189
sha256: 562e0a64bddc1cea144894f793dac6806d2a8d252f3ddfff95d0d5d844eeafea
sha512: ddadbf08a3c6b5bc1db11827eec76050cf5c2533b6f5a0979c0a8b990ecdd4ca2a43b97360be1cb56ac10c8a1e1459eaaaeb8e77f9cc686cac5420ed2042594c
ssdeep: 12288:oYmxFDoPiNf8EXiO4++lDOEcTCs0rwT3l9umqIT3l9umqMNc8:EOi589D1pdc+x8pZDpZbq8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15625AEC133A8CB18E1AF07B95031C87A837BAD199901CFECDA55F8956E3C38A162D5D7
sha3_384: 5741ba4c6e9d45ff2a743d1289d2bef63698f41e4024e3ec3c219c958a0b4df7048a47b1e23c14b429188fe3a35de46f
ep_bytes: ff250020400001000000050000000600
timestamp: 2021-08-06 17:18:11

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: OsuBuddy
FileVersion: 1.0.0.0
InternalName: Sleeky.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Sleeky.exe
ProductName: OsuBuddy
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4254228677 also known as:

LionicTrojan.Win32.Heracles.4!c
MicroWorld-eScanGen:Variant.Bulz.784906
FireEyeGen:Variant.Bulz.784906
CAT-QuickHealTrojan.AgentFC.S23213760
ALYacGen:Variant.Bulz.784906
CylanceUnsafe
SangforRiskware.Win32.Uwamson.A
K7AntiVirusUnwanted-Program ( 00581e541 )
K7GWUnwanted-Program ( 00581e541 )
CyrenW32/Trojan.UJZT-8560
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GameHack.BJI potentially unsafe
BitDefenderGen:Variant.Bulz.784906
AvastWin32:MalwareX-gen [Trj]
Ad-AwareGen:Variant.Bulz.784906
SophosGeneric PUA LG (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic.grp
EmsisoftGen:Variant.Bulz.784906 (B)
GDataGen:Variant.Bulz.784906
Antiy-AVLTrojan/Generic.ASMalwS.347EC44
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4542755
McAfeeRDN/Generic.grp
MAXmalware (ai score=80)
MalwarebytesMalware.AI.4254228677
TrendMicro-HouseCallTROJ_GEN.R002H09H921
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:MalwareX-gen [Trj]

How to remove Malware.AI.4254228677?

Malware.AI.4254228677 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment