Malware

Malware.AI.4274833881 (file analysis)

Malware Removal

The Malware.AI.4274833881 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4274833881 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.4274833881?


File Info:

name: 3703359278F891E49A99.mlw
path: /opt/CAPEv2/storage/binaries/5c2b8aac458ba24cd9e4596d027dc602577c63623492bc8a125da733666b9d19
crc32: CD66D98D
md5: 3703359278f891e49a99d11f6b559e6b
sha1: 028afbbe9eb01a3ec2435088929d88f9b4e213ff
sha256: 5c2b8aac458ba24cd9e4596d027dc602577c63623492bc8a125da733666b9d19
sha512: 1c159a6e3db8897422731f7945399cc5079bc86183e6d71dcd3c8091e43ffdf39654672ea9e9cf68628343fab2f96db6215fc3b3c72ebda99c9fe9dfdda8b639
ssdeep: 6144:RqthRs+eI/X2D2sNEAa9/WUFUP2HhcnxbZwVd:eEHDnNEAS/AYYZwf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147A45B87E5EBF631DBC6D830CD64DA9DA530E39CDE25D4B0E86984E4A853EF84D0198C
sha3_384: d1922c78d8eeed15e19e6718db90a7010c54f3f70846a236c1ebd734ab659f6cc0e20fb1a3c8289019a5af4ae8149930
ep_bytes: 558bec6aff684031400068b022400064
timestamp: 2011-03-15 04:06:07

Version Info:

0: [No Data]

Malware.AI.4274833881 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.185
MicroWorld-eScanTrojan.GenericKD.34110279
FireEyeGeneric.mg.3703359278f891e4
CAT-QuickHealW32.Zombie.A4
ALYacTrojan.GenericKD.34110279
CylanceUnsafe
ZillyaTrojan.Cosmu.Win32.12187
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3dd1 )
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.278f89
ArcabitTrojan.Generic.D2087B47
BitDefenderThetaGen:NN.ZexaF.34182.CqZ@aGBV9uib
CyrenW32/Cosmu.H.gen!Eldorado
ESET-NOD32Win32/Agent.NBJ
TrendMicro-HouseCallTROJ_SPNR.15CC13
ClamAVWin.Trojan.Cosmu-1058
KasperskyTrojan.Win32.Cosmu.bwts
BitDefenderTrojan.GenericKD.34110279
NANO-AntivirusTrojan.Win32.Cosmu.bgzaxj
AvastWin32:RansomX-gen [Ransom]
TencentVirus.Win32.Cosmu.a
Ad-AwareTrojan.GenericKD.34110279
EmsisoftTrojan.GenericKD.34110279 (B)
ComodoTrojWare.Win32.Agent.NBJ@4xjtww
VIPRETrojan.Win32.Cosmu.bwts (v)
TrendMicroTROJ_SPNR.15CC13
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.gh
SophosMal/Behav-112
IkarusTrojan.Win32.Cosmu
JiangminTrojan/Cosmu.ppf
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.13CA44
KingsoftHeur.SSC.2787082.0010.(kcloud)
MicrosoftTrojan:Win32/Zombie.A
GDataTrojan.GenericKD.34110279
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cosmu.R51515
McAfeeGenericRXNR-SA!3703359278F8
VBA32Trojan.Cosmu
MalwarebytesMalware.AI.4274833881
APEXMalicious
RisingTrojan.Zombie!8.2DA5 (RDMK:cmRtazqZA6YRCTDRdADX/kB5jVbL)
YandexTrojan.GenAsa!qZCC7vZoV+4
MAXmalware (ai score=86)
MaxSecureTrojan.Cosmu.bwts
FortinetW32/Agent.NBJ!tr
AVGWin32:RansomX-gen [Ransom]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.4274833881?

Malware.AI.4274833881 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment