Malware

Malware.AI.4274723244 removal instruction

Malware Removal

The Malware.AI.4274723244 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4274723244 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Malware.AI.4274723244?


File Info:

name: 06B6857BD7E3A5E03A67.mlw
path: /opt/CAPEv2/storage/binaries/6b3575d3836bdff8009cdc10c06704eebbd2d7ab9788fd69dd4a9c5a158d3420
crc32: AC298D8C
md5: 06b6857bd7e3a5e03a6731c84f6eff52
sha1: 6deedb8fa8c2459349e4b91c8f637c01574de8fe
sha256: 6b3575d3836bdff8009cdc10c06704eebbd2d7ab9788fd69dd4a9c5a158d3420
sha512: 351784f88e25a2c11081b6d3338b23e5a817c538876d08005654fcbff39c342b19e8efca970d7b43711450e210ec0bac5485104e54919ce0ab2627e2352de908
ssdeep: 49152:haFypT4qZHYyRMMI/MQ5VxEToPfRQbpmoCh8h2m+KBWIOOhA0xJ:ow++YIMMI/MQrqwRQbpmv+ort0X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106D5F141B98693F2F05609780077A36A5E355B28533089D3BB9C1F1E8FA52D1EE7728F
sha3_384: 82e671b1892391cee6273e93cf2bef35faf8b6fe8c7af125904dc97182effe2b9d7ee71aa64c7f9c77958f0a59293313
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Pontes Games
FileDescription: Pontes Braille Typewriter Setup
FileVersion:
LegalCopyright:
ProductName: Pontes Braille Typewriter
ProductVersion:
Translation: 0x0000 0x04b0

Malware.AI.4274723244 also known as:

CAT-QuickHealTrojan.GenericCS.S3078576
CylanceUnsafe
SangforTrojan.Win32.Ceevee.mt
CyrenW32/S-5dfbe0f1!Eldorado
SymantecTrojan.Gen
AvastWin32:Malware-gen
EmsisoftApplication.SilentInstaller (A)
F-SecureTrojan.TR/Redcap.yyggp
DrWebTrojan.KillProc.50719
ZillyaTrojan.Generic.Win32.963949
TrendMicroRansom_CVE.R002C0DFC21
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosMal/Generic-S
GDataWin32.Trojan.PSE.1HPVX37
JiangminTrojan.Gen.bmm
AviraTR/Redcap.yyggp
Antiy-AVLRiskWare[PSWTool]/Win32.NetPass
MicrosoftTrojan:Win32/Ceevee
McAfeeArtemis!06B6857BD7E3
VBA32Hoax.Gen
MalwarebytesMalware.AI.4274723244
TrendMicro-HouseCallRansom_CVE.R002C0DFC21
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
IkarusRansom.Win32
FortinetW32/KillProc.A!tr
BitDefenderThetaGen:NN.ZexaF.34606.6uZ@aClDOdp
AVGWin32:Malware-gen

How to remove Malware.AI.4274723244?

Malware.AI.4274723244 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment