Malware

Malware.AI.4287610078 removal guide

Malware Removal

The Malware.AI.4287610078 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4287610078 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the EnigmaStub malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4287610078?


File Info:

name: 5325BF81E3486B316673.mlw
path: /opt/CAPEv2/storage/binaries/f69e793660d5dbbe922c0baa7142b8f9cbcccab246706c0e7a2a6437590107e6
crc32: E8F53C90
md5: 5325bf81e3486b31667375308223fc0d
sha1: 94cd81b530b7424d4e39646224a683e9c8f6a4e3
sha256: f69e793660d5dbbe922c0baa7142b8f9cbcccab246706c0e7a2a6437590107e6
sha512: 53011805ddd64ebbc386824427fb0661ed5d5384732efb8e364d83cd37ece22d588086f3177d3213479fbc4d3ea0fa1261fb72c5be4a7ab7b232faa7c7b4ed48
ssdeep: 49152:29/5UryjhhvKyb01QzaDQSxZIxl6iJih7bzsMTQ:29hmyjDvKlNQ+Zmhq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5A533D532389480EF697638B5708E7C12D9E12768F9692DB08D5DD72E823F7384E8C6
sha3_384: 618ba75ba0d5b30e7073b133c3a913cccb4a6a27c3b1ddb0d6ad9de983ab73e26fb0dfd1f8175a37b5ea3daaf5b5a57e
ep_bytes: eb0800a203000000000060e800000000
timestamp: 2017-07-22 04:49:41

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: DIMENSIONGAMERS
FileDescription: Facebook_Message_Sender
FileVersion: 2.0.0.0
InternalName: FB_Sender.exe
LegalCopyright: Copyright © DImensionGamers 2017
LegalTrademarks:
OriginalFilename: FB_Sender.exe
ProductName: Facebook_Message_Sender
ProductVersion: 2.0.0.0
Assembly Version: 2.0.0.0

Malware.AI.4287610078 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
DrWebTrojan.Inject3.6073
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!5325BF81E348
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
BitDefenderThetaGen:NN.ZexaF.36680.dA0@ay4CwOc
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Bitrep!8.F596 (CLOUD)
SophosGeneric ML PUA (PUA)
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Win32.SGeneric
VBA32BScope.Trojan.DOTHETUK
MAXmalware (ai score=99)
MalwarebytesMalware.AI.4287610078
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.4287610078?

Malware.AI.4287610078 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment