Malware

Malware.AI.4268555474 information

Malware Removal

The Malware.AI.4268555474 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4268555474 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Malware.AI.4268555474?


File Info:

name: 646C5D1E4512849B7017.mlw
path: /opt/CAPEv2/storage/binaries/966b432f1023ce9e9e75c4e4ffa3521dc78e455354bc8792e663e223e5ddc5de
crc32: 8A87B7A2
md5: 646c5d1e4512849b70177c94e22f3f7c
sha1: 720ed6beef7a3dfd73fe7bc517efe2f4018e54ab
sha256: 966b432f1023ce9e9e75c4e4ffa3521dc78e455354bc8792e663e223e5ddc5de
sha512: cc17a63e98c21e4d61351d88c7973ad7ea833dba4d89c13a46dea665c9c318b712bafeb4f42542c35abe1e737b8d47a141eb1706753ba925cbd75d572725dfbe
ssdeep: 24576:EnaPfh0t9yeErJyAUoEP7ezj2nkoRboNG:EaHSW1VVqezindUG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1490502B2AD19C5AFF32666B8C7A0D7790DF026B81C778127F8B87D98666C3414C4E139
sha3_384: eef47a95a2706fe2d05bc3b043b560e52b27f735d22018eaeff230201d9849d4b76da66395b0fd7d7868caab26073487
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Leo, Inc.
FileDescription: Security Hack Setup
FileVersion:
LegalCopyright:
ProductName: Security Hack
ProductVersion: 1.0
Translation: 0x0000 0x04b0

Malware.AI.4268555474 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Variant.Bulz.257850
FireEyeGen:Variant.Bulz.257850
CAT-QuickHealTrojan.IGENERIC
McAfeeRDN/Generic PUP.z
CylanceUnsafe
SangforTrojan.Script.Agent.3551
BitDefenderGen:Variant.Bulz.257850
Cybereasonmalicious.e45128
BitDefenderThetaGen:NN.ZemsilF.34712.Wr0@amjRFen
CyrenINF/Autorun
SymantecTrojan.Gen.2
ESET-NOD32MSIL/HackTool.Agent.GJ
TrendMicro-HouseCallTROJ_GEN.R002C0PBA22
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:MSIL/SelfMailer.4cbe3aba
NANO-AntivirusTrojan.Win32.Gen5.ebdpwh
APEXMalicious
TencentWin32.Trojan.Spy.Wnmq
SophosGeneric PUA HC (PUA)
ComodoMalware@#14x7uk5uuf0vp
ZillyaTool.Agent.Win32.96532
TrendMicroTROJ_GEN.R002C0PBA22
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.cc
EmsisoftGen:Variant.Bulz.257850 (B)
IkarusTrojan.Script
WebrootW32.Malware.Heur
KingsoftWin32.HackTool.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Script.3551
VBA32Trojan.Script.Phonzy
ALYacTrojan.Script.3551
MAXmalware (ai score=80)
MalwarebytesMalware.AI.4268555474
YandexRiskware.Agent!hQ/012+K9s0
FortinetMSIL/Agent.GJ!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Malware.AI.4268555474?

Malware.AI.4268555474 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment