Malware

Malware.AI.4281747556 malicious file

Malware Removal

The Malware.AI.4281747556 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4281747556 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4281747556?


File Info:

name: 9B5C2668520BE236E602.mlw
path: /opt/CAPEv2/storage/binaries/ac16c3c71db067510bc57a2ad67cbcc6e81016a4dbaf1b4d64d745755aaedc9b
crc32: AA30E47F
md5: 9b5c2668520be236e6020017554f8fb5
sha1: 24ccbf94577689fcb08e80b64c23f469e3b93b6d
sha256: ac16c3c71db067510bc57a2ad67cbcc6e81016a4dbaf1b4d64d745755aaedc9b
sha512: ca6f7d2ce2653904ebea7f01c12dd761e8d9a2f61440d8409f290c64d09fea4817a22e8830003ad501ca9af711b5d0f5db5a557795b9115387c70b2edd1a3560
ssdeep: 49152:aQqpO57peWqVzWU/I5WA/ZDzP/JjRoGxxdL0:vuL/W/Z1R1g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183A533063386C8FAD61C3533650F4E5372B2DA64E0972E57170EE77DED281909BA2F86
sha3_384: f43d9952abb6897683d91df5c7108c60a081b8e667a6ffb8a422456a9ea725bb5517a5f9355be71853d5e4337f078f02
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Malware.AI.4281747556 also known as:

BkavW32.AIDetect.malware2
LionicRiskware.MSIL.PCOptimizer.1!c
tehtrisGeneric.Malware
CAT-QuickHealRisktool.NSIS.Pcoptimizer.A
CylanceUnsafe
SangforAdware.MSIL.MyPCBackup.F
K7AntiVirusAdware ( 004bd8f61 )
K7GWAdware ( 004bd8f61 )
CrowdStrikewin/grayware_confidence_100% (W)
CyrenW32/Trojan.GHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/MyPCBackup.G potentially unwanted
APEXMalicious
Paloaltogeneric.ml
NANO-AntivirusTrojan.Win32.MyPCBackup.edpzhe
ViRobotAdware.Mypcbackup.2149302
ComodoMalware@#1x5bcnzbglj1
F-SecureHeuristic.HEUR/AGEN.1203192
DrWebProgram.Unwanted.1152
Trapminemalicious.moderate.ml.score
SophosGeneric PUA CE (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.MSIL.Crypt.o
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1220205
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.5FE4
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ZoneAlarmnot-a-virus:RiskTool.MSIL.PCOptimizer.qd
MicrosoftTrojan:Win32/Occamy.CAC
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BundleInstaller.R194324
MalwarebytesMalware.AI.4281747556
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_GEN.R002H0CFF22
YandexRiskware.PCOptimizer!jcqAEkDv+R0
IkarusPUA.MSIL.Mypcbackup
FortinetRiskware/PCOptimizer

How to remove Malware.AI.4281747556?

Malware.AI.4281747556 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment