Malware

Malware.AI.4287028941 (file analysis)

Malware Removal

The Malware.AI.4287028941 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4287028941 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4287028941?


File Info:

name: 997F00156BDF84FE1E9E.mlw
path: /opt/CAPEv2/storage/binaries/a8cdf39a5c283c5b5862b079bd50b68661c4a140f71862f1e605fb1a86be3e5b
crc32: BA45F2A5
md5: 997f00156bdf84fe1e9e20311e544144
sha1: f69669aa9b323ec1bda100c271ba7a704081774d
sha256: a8cdf39a5c283c5b5862b079bd50b68661c4a140f71862f1e605fb1a86be3e5b
sha512: 5e0a79254bab4b678097a4051081a81f73647abe0c86e03dba5274e7f2b4f2da53bf7aea180f47637627ef9c9cae973f1c78817c162dbab5102af8c87a95490c
ssdeep: 24576:r4/SmzjDhH0N/beYG26i7WfVlie5NVI22CDqs2oY1LP7B:s/SYhHS/bRG2ifVlfR2CDq4WLd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B25523E6A3D96868CA3C063497716A9B4325EF2C1ED5E6092492B408FFFD10BBD4335D
sha3_384: 288b1bea561e83ea9356b2916f3723cadc34b09ff364c3377e400437c4cc5e7fe8ebbca7aa055917553b9b5785ff4e21
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-06-24 22:26:21

Version Info:

Translation: 0x0000 0x04b0
FileDescription: WindowsApplication4
FileVersion: 1.0.0.0
InternalName: WindowsApplication4.exe
LegalCopyright: Copyright © 2014
OriginalFilename: WindowsApplication4.exe
ProductName: WindowsApplication4
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4287028941 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Variant.Kazy.474577
FireEyeGeneric.mg.997f00156bdf84fe
McAfeeGenericRXFU-OM!997F00156BDF
CylanceUnsafe
ZillyaTrojan.DllInject.Win32.7812
SangforRiskware.Win32.Agent.ky
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.56bdf8
ArcabitTrojan.Kazy.D73DD1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/DllInject.AJ potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PGR21
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Kazy.474577
NANO-AntivirusTrojan.Win32.Zusy.dftwcx
Ad-AwareGen:Variant.Kazy.474577
EmsisoftGen:Variant.Kazy.474577 (B)
ComodoMalware@#1uu1ykri63gdr
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PGR21
McAfee-GW-EditionGenericRXFU-OM!997F00156BDF
SophosMal/MSIL-AX
Paloaltogeneric.ml
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1109700
Antiy-AVLTrojan/Generic.ASMalwS.AAA9FA
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Skeeyah.oa!s1
MicrosoftBackdoor:Win32/Bladabindi!ml
ViRobotTrojan.Win32.Z.Kazy.1404928
GDataGen:Variant.Kazy.474577
CynetMalicious (score: 99)
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Kazy.474577
MAXmalware (ai score=87)
MalwarebytesMalware.AI.4287028941
APEXMalicious
TencentWin32.Trojan.Kazy.Hupr
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
WebrootW32.Gen.BT
AVGWin32:Malware-gen
PandaTrj/Chgt.D

How to remove Malware.AI.4287028941?

Malware.AI.4287028941 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment