Malware

Malware.AI.4288065495 malicious file

Malware Removal

The Malware.AI.4288065495 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4288065495 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality

How to determine Malware.AI.4288065495?


File Info:

name: 39A8003780CF0E023144.mlw
path: /opt/CAPEv2/storage/binaries/9ab1f1c56d5d089ae6409c85383f7b0828665625cc5b99cef1ed33ea80c28db4
crc32: 21C7CD86
md5: 39a8003780cf0e0231443374454095e6
sha1: 7c7b8228f45b4f1f6b2d5665de2e14255d6a3e82
sha256: 9ab1f1c56d5d089ae6409c85383f7b0828665625cc5b99cef1ed33ea80c28db4
sha512: 67bca897f7fa55c7ee7490842f93d73615335e49f1987575e530c56671b5fbf3e658c86362754b79b6a16b709eba9ce83ea0545226e9fe515e22fd6cfaf59415
ssdeep: 24576:LZB2HNFI46kxUJDhrRICn1f53LY4R7UlenxcgDN3c2KD7:LZYHNFI4PmnRICT3LRR7Ulenf3Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1552346BFCA4076C0404B709C1EA6B08539FFB5A76063CF87523C6C7C79A706A65BE6
sha3_384: a304fd00d63addc62c17c8ed7239041d7256476fb40aff677e7571e59f9b7c8d4d5dfba0e428399b159e821a9eddc530
ep_bytes: e89f28000050e8832a01000000000090
timestamp: 2006-08-04 18:28:08

Version Info:

0: [No Data]

Malware.AI.4288065495 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTool.ShutDown.14
McAfeeArtemis!39A8003780CF
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004ba4531 )
K7GWUnwanted-Program ( 004ba4531 )
CyrenW32/Risk.AXVY-4226
ESET-NOD32Win32/PrcView potentially unsafe
APEXMalicious
Paloaltogeneric.ml
NANO-AntivirusTrojan.Win32.Reboot.cxpnoq
SUPERAntiSpywareTrojan.Agent/Gen-Rebooter
AvastFileRepMetagen [Malware]
VIPRETrojan.Win32.Generic!BT
WebrootW32.Malware.Heur.Dkvt
Antiy-AVLTrojan/Generic.ASMalwS.28B2EBC
ViRobotTrojan.Win32.Z.Reboot.1303627
MicrosoftTrojan:Win32/Wacatac.A!ml
VBA32BackDoor.IRC.Chazz
MalwarebytesMalware.AI.4288065495
TrendMicro-HouseCallTROJ_GEN.R002H06K721
FortinetRiskware/Reboot
AVGFileRepMetagen [Malware]

How to remove Malware.AI.4288065495?

Malware.AI.4288065495 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment