Malware

Malware.AI.4273990673 removal instruction

Malware Removal

The Malware.AI.4273990673 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4273990673 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the StormKitty malware family
  • Binary compilation timestomping detected

How to determine Malware.AI.4273990673?


File Info:

name: C9B42A5736DC621A27AF.mlw
path: /opt/CAPEv2/storage/binaries/b1ae4b96a33486d7abc09f7405c450934531920de0d44cde7e628f08b753e6d9
crc32: 5A90BBB0
md5: c9b42a5736dc621a27af89075e9cd8b4
sha1: 5464f9a113e2b7078c9566b87e8eec5d648a88f5
sha256: b1ae4b96a33486d7abc09f7405c450934531920de0d44cde7e628f08b753e6d9
sha512: c331f5352f7414bf08da0d27bf3af5235742f4edc20fda6f0f5bbc31c2787f7c753c829a89c872b39b68de348185a5dc19a9fecfd837e63109f9c4f4c951e329
ssdeep: 6144:PbAD4AecSEuNYnMuBAnLzuyvwWoSF45AcTG8OnXKxRvcSEuNYnMuBAnLzuyvwWob:3FEuNYB8z1wWo4sAIGtX+VFEuNYB8z1A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A84AE153775871BE2AF0BF845A9633093F4B3823867C74A9E6664CC3B65FCC608649B
sha3_384: 31796990512bc6ebd781cadd349665eb17f66da76286cea3846f424d5d1fb3c027047d70df359b9de628350f7427f1ad
ep_bytes: ff250020400068747470733a2f2f6769
timestamp: 2096-05-11 15:31:24

Version Info:

Translation: 0x0000 0x04b0
Comments: Prynt Data Recovery Tool
CompanyName: Prynt Software
FileDescription: Prynt Stealer 5.2
FileVersion: 1.0.0.0
InternalName: Prynt Stealer 5.2.exe
LegalCopyright: Copyright @FlatLineStealerOfficial
LegalTrademarks: Prynt Software
OriginalFilename: Prynt Stealer 5.2.exe
ProductName: Prynt Stealer 5.2
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4273990673 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (moderate confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.21787
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacIL:Trojan.MSILZilla.21787
VIPREIL:Trojan.MSILZilla.21787
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.736dc6
ESET-NOD32a variant of Win32/RiskWare.HackTool.Agent_AGen.B
APEXMalicious
BitDefenderIL:Trojan.MSILZilla.21787
Ad-AwareIL:Trojan.MSILZilla.21787
EmsisoftIL:Trojan.MSILZilla.21787 (B)
FireEyeIL:Trojan.MSILZilla.21787
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataIL:Trojan.MSILZilla.21787
ArcabitIL:Trojan.MSILZilla.D551B
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.C5045236
MAXmalware (ai score=89)
MalwarebytesMalware.AI.4273990673
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/HackTool

How to remove Malware.AI.4273990673?

Malware.AI.4273990673 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment