Malware

Malware.AI.4288253594 information

Malware Removal

The Malware.AI.4288253594 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4288253594 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Malware.AI.4288253594?


File Info:

name: 3908915F0CD7F64E9B9A.mlw
path: /opt/CAPEv2/storage/binaries/9a547f4075a794047ebb39f7bcaf5f3fdfe71a007aa55fd0d0ab230466972c50
crc32: 7FD13EF6
md5: 3908915f0cd7f64e9b9a4f45f223a165
sha1: 600698a560e815b8fac2242621930909fb8130f8
sha256: 9a547f4075a794047ebb39f7bcaf5f3fdfe71a007aa55fd0d0ab230466972c50
sha512: 922b666196d56fe391b1b0a4d1a05b40fbd1fdea48f44aa5a2d7f269b7fc7971849f6707463cb0265f9c8317852da47b43dd47b4a7e0b862edbb23c9b2bf99ee
ssdeep: 196608:381GHdK+lfBiUj7PgCLYoCYxTRR1LUXXt6u1FRqif2cdP5CXDr9:M1SXoI7PjCklR1L+Xt6Y/qilP5e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EBB633FEE875A9E4E16BD17CC3AD1B1EA27E44DE132B3D4D8A3CBE50E5C85497412088
sha3_384: 40b8f46a99b36f3cad65d66d21c652c9de289e2aabdede79f40a22c2dcdf91aa07e886a0704e0fd53ab41e09eba59d67
ep_bytes: 60be004041008dbe00d0feff57eb0b90
timestamp: 2012-12-30 08:49:49

Version Info:

FileVersion: 2.0.6.9
Comments: Compiled 2019Q3
FileDescription: http://www.xyboot.com/
ProductVersion: 2.0.6.9
LegalCopyright: Copyright © Sinoxer
Productname: USB3 Drivers Smart Install x86
Translation: 0x0804 0x04b0

Malware.AI.4288253594 also known as:

LionicTrojan.Win32.Generic.4!c
McAfeeArtemis!3908915F0CD7
CylanceUnsafe
SangforTrojan.Win32.Autoit.NBB
K7AntiVirusTrojan ( 0051918e1 )
AlibabaPacked:Win32/Neshta.82f016f6
K7GWTrojan ( 0051918e1 )
SymantecTrojan.Gen.2
Paloaltogeneric.ml
NANO-AntivirusTrojan.Win32.Stealer.fgibef
SophosMal/Generic-R
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASCommon.1B8
GridinsoftRansom.Win32.AzorUlt.sa
MicrosoftTrojan:Win32/Vigorf.A
GDataWin32.Trojan.Agent.3GYN2R
MalwarebytesMalware.AI.4288253594
YandexRiskware.Autoit!aKTZO3TXeo4
FortinetRiskware/Application

How to remove Malware.AI.4288253594?

Malware.AI.4288253594 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment