Malware

Malware.AI.4280550437 information

Malware Removal

The Malware.AI.4280550437 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4280550437 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4280550437?


File Info:

name: 151E8BCD0976B3884682.mlw
path: /opt/CAPEv2/storage/binaries/b47aa8f692b8e0f5ec61db315e67407d6cb0b1d324f8c3d33693700e1c7c11f5
crc32: 8C6ACFEA
md5: 151e8bcd0976b38846827c748f4e02cd
sha1: 8f4e15aec2b2fe2c128a6e0cba7232f6022d9783
sha256: b47aa8f692b8e0f5ec61db315e67407d6cb0b1d324f8c3d33693700e1c7c11f5
sha512: b11f1098edd5bd75c8468f55284e66d2cb5ecb22e208c8216571ca0bb9be7b141576131a7097e74222ac631dbc0e882c4d96c34f934da9b7a49fd2b689e51a2a
ssdeep: 24576:pM5KNB6i7VOYKxEs525VntGSyjD/ElnsD+b2dYF4+dhiJ7ZvaBXGsUD8+wZX9L/:ptb4ms54VtGNAxs4E+/2NvaxSdkX1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195A53320A2E6DDD7F099B53324A3416912F1CA9AB82019F39BD0AF67E4753717B06CC6
sha3_384: f888aecea1e80d54355d7ff3512a54d911efbc2c89479e2f4d204ebea361f3994af1d6b4ad4e82ba07de3ac47d906fca
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Malware.AI.4280550437 also known as:

tehtrisGeneric.Malware
DrWebProgram.Unwanted.1152
MicroWorld-eScanTrojan.GenericKD.46407541
FireEyeTrojan.GenericKD.46407541
CAT-QuickHealPUA.NSIS.PCOptimizer.E
McAfeeArtemis!151E8BCD0976
CylanceUnsafe
SangforTrojan.Win32.Agent.aa
K7AntiVirusAdware ( 004bd8f61 )
K7GWAdware ( 004bd8f61 )
CyrenW32/Trojan.GHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32MSIL/MyPCBackup.G potentially unwanted
TrendMicro-HouseCallADW_MyPCBackup.component
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.46407541
NANO-AntivirusRiskware.Win32.MyPCBackup.ebhdgr
ViRobotAdware.Mypcbackup.2147632
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.46407541
SophosGeneric PUA IP (PUA)
ZillyaTool.BackupMyPC.Win32.59
TrendMicroADW_MyPCBackup.component
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftTrojan.GenericKD.46407541 (B)
Ikarusnot-a-virus:RiskTool.BackupMyPC
GDataNSIS.Adware.MyPCBackup.E
WebrootW32.Mypcbackup
AviraHEUR/AGEN.1220205
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwNS.6EAF
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.CB4
CynetMalicious (score: 100)
VBA32CIL.HeapOverride.Heur
MalwarebytesMalware.AI.4280550437
APEXMalicious
YandexRiskware.PCOptimizer!V0EFEh+O6D0
SentinelOneStatic AI – Malicious PE
FortinetRiskware/PCOptimizer
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Malware.AI.4280550437?

Malware.AI.4280550437 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment