Malware

Malware.AI.4260217998 removal instruction

Malware Removal

The Malware.AI.4260217998 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4260217998 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4260217998?


File Info:

name: 656E4493E1CF45C3FDDF.mlw
path: /opt/CAPEv2/storage/binaries/fa0014f62779d2db554ada4d33bbb40019d84ffbafa2b67af6417ff9d4fa8e0f
crc32: B74B8862
md5: 656e4493e1cf45c3fddf440dbe804a80
sha1: 688b8335507a886b50ed289dbb96315db3c310c4
sha256: fa0014f62779d2db554ada4d33bbb40019d84ffbafa2b67af6417ff9d4fa8e0f
sha512: 736ab6911624f02d3bb8152de6dbcc61ee31a90691ee70cb7e925d64e37147096b26817dc5970f5b0d8643988bcb77b48c58d8a5038fc3b0fbb646b503b144ab
ssdeep: 24576:MiQsFhBhmAWAdnQxlfj6Yak6ncEL6C1cjbdjjJcp:qsFlmAWAdQTfj6Yat6C69mp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B35D122F5D78073C5A322718DBEF77A963DB93A0327C5AB27C81D255EA0541762A333
sha3_384: 573ba04557becbf78619ff56305e009ae4e714e7488d9d2cf4e16a6e95d10718b4079767ba150d2c40fbd097361dd838
ep_bytes: e8dec20000e989feffffcccccccccccc
timestamp: 2012-02-04 22:43:24

Version Info:

FileVersion: 2.1.0.1
Comments: PMSS是群英湛江机房创作,集Ping、Mstsc、Telnet、Ssh连接于一体的便捷办公室软件.
FileDescription: PMSS是群英湛江机房创作,集Ping、Mstsc、Telnet、Ssh连接于一体的便捷办公室软件.
LegalCopyright: _陈观龙_
Translation: 0x0804 0x04b0

Malware.AI.4260217998 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.656e4493e1cf45c3
SkyhighBehavesLike.Win32.Dropper.tc
MalwarebytesMalware.AI.4260217998
Cybereasonmalicious.5507a8
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Autoit-6753917-0
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
VaristW32/Trojan.IJBN-1595
Antiy-AVLTrojan[Spy]/Win32.Autoit
Kingsoftmalware.kb.a.852
XcitiumTrojWare.Win32.Hider.REXR@5364l6
ViRobotTrojan.Win32.A.Agent.690283
GDataWin32.Trojan.PSE.R2WKDE
GoogleDetected
McAfeeArtemis!656E4493E1CF
VBA32IMWorm.Sohanad
Cylanceunsafe
YandexTrojan.GenAsa!i9rai7w7/WE
IkarusTrojan.Win32
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Malware.AI.4260217998?

Malware.AI.4260217998 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment