Malware

About “Malware.AI.4287330604” infection

Malware Removal

The Malware.AI.4287330604 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4287330604 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the A310Logger malware family
  • Anomalous binary characteristics

How to determine Malware.AI.4287330604?


File Info:

name: B173D79A854DD2E46706.mlw
path: /opt/CAPEv2/storage/binaries/9102d21f260940676a7d0f9dc98518e3bcb15ab9ce460a62163cc6d763da61c1
crc32: EC025485
md5: b173d79a854dd2e46706c4cec8d7f22e
sha1: b5558dd8acb571e95bee2391bdda88c33d5473cd
sha256: 9102d21f260940676a7d0f9dc98518e3bcb15ab9ce460a62163cc6d763da61c1
sha512: 305ad457275ec4fb1155b59fb43b35e086989bf5ded95f4872423c385f5ab8c9c42ca93c85f6b3e8215d3fa53b902428992df026835c9a73d5026852aca26561
ssdeep: 6144:bLVEipLOn9HrP6DA3xHR5HMhHxZhSdX/wrAWmuYtsBM5G4cqmNR1j08XfSHjbsB8:bL9TYP+Hx3rwJ5GUwnjXfS8qlOZM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166D49D2EB390F33AEC65C1B12698426594ACF93661852C1BD7821B1D77F5CE3E27132B
sha3_384: 4b185516e0386e1e6a2efec8dc6fe3aa9f9594856252c9dc8c3de8817d36503f66cdade3bdde6902a665828da64b044e
ep_bytes: 6874f14500e8eeffffff000000000000
timestamp: 2022-07-11 23:30:41

Version Info:

0: [No Data]

Malware.AI.4287330604 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.90728
FireEyeGeneric.mg.b173d79a854dd2e4
ALYacGen:Variant.Symmi.90728
CylanceUnsafe
Sangfor[MICROSOFT VISUAL BASIC 5.0]
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ERUA
APEXMalicious
BitDefenderGen:Variant.Symmi.90728
AvastWin32:DarkVB-A [Trj]
Ad-AwareGen:Variant.Symmi.90728
EmsisoftGen:Variant.Symmi.90728 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGen:Variant.Symmi.90728
Trapminesuspicious.low.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.90728
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
ArcabitTrojan.Symmi.D16268
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32Malware-Cryptor.VB.gen.1
MalwarebytesMalware.AI.4287330604
RisingWorm.WBVB!8.103CC (TFE:dGZlOgV2E1ZSAZ+IDA)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.34786.NmW@augfzso
AVGWin32:DarkVB-A [Trj]
Cybereasonmalicious.a854dd

How to remove Malware.AI.4287330604?

Malware.AI.4287330604 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment