Malware

About “Malware.AI.4269570674” infection

Malware Removal

The Malware.AI.4269570674 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4269570674 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk

How to determine Malware.AI.4269570674?


File Info:

name: 256409F37D12E3813535.mlw
path: /opt/CAPEv2/storage/binaries/bb3600e8773a1ab2f349a684a0f4286aff3108d089d911d24e3fe64f3d61c76c
crc32: 6B14C5B0
md5: 256409f37d12e38135357ebdd5410de7
sha1: 61944230784e2e88fb2e83bb1b2bf6f00ad0bd6a
sha256: bb3600e8773a1ab2f349a684a0f4286aff3108d089d911d24e3fe64f3d61c76c
sha512: 01f6f319e846d35b985d52952946dced07a6ed4f7aac5c52e7566ea9fbc52dcb41d3fcb80231eea0fd6d5c08cc8b6f6936b3c575de346e0ea4790b45f9ce389b
ssdeep: 24576:8KHr0eL3qFH1/mmcLu8voAHTJ/2Armxnq05oDSAom:8KQe7qFH1+mcLu8voAHT92rxnq05QF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149153336A3167792E0CB17B818E67F422538F06F9D4F9673590EE48FBCE01CA5D521A8
sha3_384: 991fcdec67584f58c0652f533f20f5dd5971bc772ed50ca9b07b6f222969757ab6f7dcee52e432774830be871b6e0c85
ep_bytes: 60be003044008dbe00e0fbffc7879cd0
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: By:Noime QQ:562628018
FileDescription: IMEIToolx64
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Malware.AI.4269570674 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Jaik.69429
ALYacGen:Variant.Jaik.69429
MalwarebytesMalware.AI.4269570674
VIPREGen:Variant.Jaik.69429
SangforTrojan.Win32.Agent.Vc6w
CrowdStrikewin/malicious_confidence_70% (W)
APEXMalicious
BitDefenderGen:Variant.Jaik.69429
AvastWin32:Malware-gen
EmsisoftGen:Variant.Jaik.69429 (B)
DrWebTrojan.MulDrop20.3521
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.256409f37d12e381
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Generic.anhj
WebrootW32.Trojan.GenKD
GoogleDetected
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Zpevdo.B
ArcabitTrojan.Jaik.D10F35
GDataGen:Variant.Jaik.69429
CynetMalicious (score: 100)
McAfeeArtemis!256409F37D12
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H09HJ22
IkarusTrojan-Dropper.Win32.Injector
MaxSecureTrojan.Malware.7164915.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.37d12e
PandaTrj/Chgt.AD

How to remove Malware.AI.4269570674?

Malware.AI.4269570674 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment