Malware

About “Malware.AI.4258152913” infection

Malware Removal

The Malware.AI.4258152913 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4258152913 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4258152913?


File Info:

name: C2FDF19ECE5123F577FE.mlw
path: /opt/CAPEv2/storage/binaries/ef0de587b17de348da82d9c36a73afee80da344443cd5416e96b667fa5167a68
crc32: 42EEA8FB
md5: c2fdf19ece5123f577fecd2e9e79023b
sha1: 80a612e7e4410b1d5ae5a4ca491597dfee8ac56f
sha256: ef0de587b17de348da82d9c36a73afee80da344443cd5416e96b667fa5167a68
sha512: c2ad57fbf7023f4e970ebaaa191bcdbbadd40ce8a81e552b6e2968205a51bdebba4d75e1e9e99a1897668b129554d7a18df5715bff245dcf68feac298a4b0bbb
ssdeep: 24576:a1X5rmp9BKFW/ar7ZyrtRFiwlDNSCyK+gE8lFjuFPt5ZzgTy6GDuqMjlvFwDXn4l:a2vrQOt7ipCyK0uFbcDJUlhAnw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BA5336263C1DECBE3D21EF2C49BC939B3B5AA0C66E417792B413F38D5640752A19BC4
sha3_384: acc71d44eeffa637541d9633a4c80559bf0ef1ccfaf6ce6000f8444dc75097f13760be7dfb842f064aef186883d10f5b
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Malware.AI.4258152913 also known as:

BkavW32.AIDetect.malware2
LionicRiskware.MSIL.PCOptimizer.1!c
Elasticmalicious (high confidence)
DrWebProgram.Unwanted.1152
CAT-QuickHealRisktool.NSIS.Pcoptimizer.A
McAfeeArtemis!C2FDF19ECE51
MalwarebytesMalware.AI.4258152913
ZillyaDownloader.Generic.Win32.4824
SangforPUP.Win32.Presenoker.mt
CrowdStrikewin/grayware_confidence_100% (W)
K7GWAdware ( 004bd8f61 )
K7AntiVirusAdware ( 004bd8f61 )
CyrenW32/Trojan.GHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MyPCBackup.D potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CK321
Paloaltogeneric.ml
Kasperskynot-a-virus:RiskTool.MSIL.PCOptimizer.b
NANO-AntivirusRiskware.Win32.MyPCBackup.eivezi
AvastWin32:Malware-gen
EmsisoftApplication.PCBackOpt (A)
ComodoMalware@#2othe677sqvj0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosGeneric PUA IA (PUA)
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.Malware
AviraHEUR/AGEN.1220205
Antiy-AVLTrojan/Generic.ASMalwNS.6EAF
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ZoneAlarmnot-a-virus:RiskTool.MSIL.PCOptimizer.b
MicrosoftTrojan:Win32/Occamy.CEF
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BundleInstaller.R194324
VBA32CIL.HeapOverride.Heur
APEXMalicious
YandexRiskware.PCOptimizer!2BL7tJr9RVM
FortinetRiskware/PCOptimizer
AVGWin32:Malware-gen

How to remove Malware.AI.4258152913?

Malware.AI.4258152913 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment