Malware

Malware.AI.4257745158 malicious file

Malware Removal

The Malware.AI.4257745158 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4257745158 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Malware.AI.4257745158?


File Info:

name: B78BCAE0DD8072B4F1DE.mlw
path: /opt/CAPEv2/storage/binaries/d67d765999456c298d370648fd28679e1fd384305369f2fdc0e713e0f1ab34b7
crc32: 9AAF17C2
md5: b78bcae0dd8072b4f1de9358943fc8b0
sha1: 6df047e5829c7f1746000b7595a2332cf8d101d3
sha256: d67d765999456c298d370648fd28679e1fd384305369f2fdc0e713e0f1ab34b7
sha512: 24aa6da08b34f57d8ea3fa5eef9318c95bcab78b58044a6cbf963f4094491473491f8aada44220397a508b0d8817d423b430dc79a2e66be640c9e45e8920bfd9
ssdeep: 24576:CPatCg7EP0DHcziJ6r01J8d5FUG39qaZGyC35/QmldAnC+sdWpUJfiNHc7tP:JtV7EP0ImzX8PFUS/Gxp/QmrAnC+sdWO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163552392377CC548C25552F35B8BD2FA6601EDD208A2334BE6F34F5EAA507479D0A1BC
sha3_384: c55e436e4e85efef01ad148084ba64934452bb69c30a59d9c241f1a297dbe3c1a013d38596cdde61f24c3311a316c4e8
ep_bytes: 60be003047008dbe00e0f8ff57eb0b90
timestamp: 2008-06-12 08:51:05

Version Info:

FileDescription:
FileVersion: 3, 2, 12, 1
CompiledScript: AutoIt v3 Script : 3, 2, 12, 1
Translation: 0x0809 0x04b0

Malware.AI.4257745158 also known as:

LionicTrojan.Win32.Autoit.m8eX
MicroWorld-eScanTrojan.Generic.11578963
FireEyeGeneric.mg.b78bcae0dd8072b4
ALYacTrojan.Generic.11578963
ZillyaTrojan.Blocker.Win32.31971
Cybereasonmalicious.0dd807
APEXMalicious
BitDefenderTrojan.Generic.11578963
AvastWin32:Malware-gen
Ad-AwareTrojan.Generic.11578963
EmsisoftTrojan.Generic.11578963 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
SophosGeneric ML PUA (PUA)
GDataTrojan.Generic.11578963
JiangminBackdoor/RBot.vut
WebrootW32.Trojan.Gen
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.DB0AE53
MicrosoftTrojan:Win32/Wacatac.A!ml
McAfeeArtemis!B78BCAE0DD80
MalwarebytesMalware.AI.4257745158
TrendMicro-HouseCallTROJ_GEN.R002H09KO21
eGambitUnsafe.AI_Score_99%
AVGWin32:Malware-gen

How to remove Malware.AI.4257745158?

Malware.AI.4257745158 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment