Malware

Should I remove “Malware.AI.4275146826”?

Malware Removal

The Malware.AI.4275146826 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4275146826 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.4275146826?


File Info:

name: 3961D14BCC96B58BB7AF.mlw
path: /opt/CAPEv2/storage/binaries/a1970c8a1782c45cd1966f94c72a9c595597735fd51f9fc8d0be79a4af62dafc
crc32: BC4C9B6D
md5: 3961d14bcc96b58bb7af645f95dc03be
sha1: edf5f53b7fd6b0a657b34bc370576b2e76e4fd2a
sha256: a1970c8a1782c45cd1966f94c72a9c595597735fd51f9fc8d0be79a4af62dafc
sha512: 76d868053294d8ae1ce7dcc11c82280e5de6b2a266e73c13a6aa1b0b58987805d57997cb30b3e907e54fbd970e258c69be56d7a60bfb43c680651f31a5b1179f
ssdeep: 6144:8pC9EWBHHWf9LCtkMjipacz96xhdKlQ3KJ4h/fqEvzGCdVTUJjYWCYhTq6ymA:bpBH2cNiDz9AhEDwJXdV+jMe
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14394936E1FF86109D7519B3458F6EF5940BE6F433D0A9A1A14A1B984FF31F8CBE0094A
sha3_384: c4175a962face8047f5669e2f2b359d29bf5e747aa348052db65f0a4aec48d9a55dedb4af3347b075aef45d62b18d5e8
ep_bytes: ff2500a0400000133008001200000000
timestamp: 2046-12-21 14:41:34

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: YoBoi
FileVersion: 1.0.0.0
InternalName: BaZookaNORDY.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: BaZookaNORDY.exe
ProductName: YoBoi
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4275146826 also known as:

LionicTrojan.Win32.Ursu.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.232269
FireEyeGeneric.mg.3961d14bcc96b58b
McAfeeRDN/Generic PUP.z
CylanceUnsafe
ZillyaTool.BruteForce.Win32.6210
SangforTrojan.Win32.Wacatac.DA
K7AntiVirusTrojan ( 7000001c1 )
AlibabaTrojan:Win32/VMProtBad.0d9f722d
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.bcc96b
BitDefenderThetaGen:NN.ZemsilF.34160.zu0@aOfmqsn
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/HackTool.BruteForce.AGT
APEXMalicious
BitDefenderGen:Variant.MSILPerseus.232269
AvastWin32:Malware-gen
Ad-AwareGen:Variant.MSILPerseus.232269
SophosMal/Generic-R + Mal/VMProtBad-A
TrendMicroTROJ_GEN.R002C0RL921
McAfee-GW-EditionRDN/Generic PUP.z
EmsisoftGen:Variant.MSILPerseus.232269 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1140535
MAXmalware (ai score=86)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.MSILPerseus.232269
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4882090
ALYacGen:Variant.MSILPerseus.232269
MalwarebytesMalware.AI.4275146826
TrendMicro-HouseCallTROJ_GEN.R002C0RL921
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:XdaowbC5iASQiMcM5iFZ4Q)
IkarusPUA.VMProtect
FortinetPossibleThreat.PALLAS.H
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.104158312.susgen

How to remove Malware.AI.4275146826?

Malware.AI.4275146826 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment