Malware

Malware.AI.4260148259 malicious file

Malware Removal

The Malware.AI.4260148259 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4260148259 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Malware.AI.4260148259?


File Info:

name: EC3E39E436B6903C1F93.mlw
path: /opt/CAPEv2/storage/binaries/ed7a5149272ef84e5204f1044115eb6158b2b1b1c1bf081a8e08893667e17614
crc32: 0D65ACBE
md5: ec3e39e436b6903c1f93c4735db28b51
sha1: fc7334787a7dd705f419aa8bb1e72595a2bc5586
sha256: ed7a5149272ef84e5204f1044115eb6158b2b1b1c1bf081a8e08893667e17614
sha512: c25423d2f375569da1850b9fa52bf9f8f45ec7b3828b436533980ebb5719517945be32ca92497e8fa5e8956506fd87b54fe880ab48c61c9a0214360def1addd4
ssdeep: 12288:dv3T6zSZZME35U0rgOx+IZHJ1lcyngMY0iGmsGDzjTxhPGBPSZxNv1k9zk2j:dv3RQSTi+Tlc4Fi4GDZNdkhj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DD423C6CE700C77E558E679120EF60256A8E5BF102B864AC5BB44168C63EC3BB7B479
sha3_384: e3667c01894166ea7db1b98275c972001c5855aef25e37ef019aaec0b2f350962e16afa76363e43dc544096318fe67bc
ep_bytes: 53680780000032dbff1540304000e886
timestamp: 2015-07-02 21:57:42

Version Info:

0: [No Data]

Malware.AI.4260148259 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fugrafa.8397
FireEyeGeneric.mg.ec3e39e436b6903c
CAT-QuickHealTrojan.Reconyc.5946
ALYacGen:Variant.Fugrafa.8397
MalwarebytesMalware.AI.4260148259
VIPREGen:Variant.Fugrafa.8397
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3dd1 )
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.436b69
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.RGL
APEXMalicious
ClamAVWin.Trojan.Mikey-9958102-0
KasperskyHEUR:Trojan.Win32.WhiteAtlas.gen
BitDefenderGen:Variant.Fugrafa.8397
NANO-AntivirusTrojan.Win32.Agent.dufetd
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Fugrafa.8397
DrWebTrojan.Reconyc.1
ZillyaDropper.Agent.Win32.208395
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Fugrafa.8397 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Agent.bzrh
AviraHEUR/AGEN.1207379
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.6
MicrosoftTrojan:Win32/Zbot.SIBD16!MTB
ZoneAlarmHEUR:Trojan.Win32.WhiteAtlas.gen
GDataWin32.Trojan-Spy.Zbot.DB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C956752
McAfeeGenericRXAA-AA!EC3E39E436B6
CylanceUnsafe
YandexTrojan.GenAsa!1QExywRk7RA
FortinetW32/Agent.RGL!tr
BitDefenderThetaGen:NN.ZexaF.34806.NqZ@aid8ZPm
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.4260148259?

Malware.AI.4260148259 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment