Malware

Malware.AI.4291746924 information

Malware Removal

The Malware.AI.4291746924 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4291746924 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4291746924?


File Info:

name: 1414BE7A6E80C6B26252.mlw
path: /opt/CAPEv2/storage/binaries/e211a59ce5ccb6cd3c2db1486e5c1eda513c5dba64a096179f16284d70b07365
crc32: E12F5564
md5: 1414be7a6e80c6b2625284205c8b6892
sha1: 9d7f14439b5641bde392ca9cb65d3073725801e3
sha256: e211a59ce5ccb6cd3c2db1486e5c1eda513c5dba64a096179f16284d70b07365
sha512: fea92f418308fe6dde54a2b9441bfb4123e09d069770913e696adb8a09122e110e1a9fc533879153b918d1f43156d30463061b2f232c6738639f40bf0d0584b4
ssdeep: 24576:aEhRBbltQFnAAtsTjtzs/yr3c6UgB5SFc+/Ka19Or1xQEjV3Z37B949ParBiuVvv:aobMxIS/01Ug++DB7rqarTVt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BA53306F388FA7AE32F2C784593FA55437A744A057923274FACAE67DD1177280B26C1
sha3_384: 24c0db419d70bcf9f3d7d14363cbfdd0e1696a01c2d70e90035f0c5bcdde0e5ec4dfc8bafc1c1bab2bd1047273c3fb2c
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Malware.AI.4291746924 also known as:

BkavW32.AIDetect.malware2
LionicRiskware.MSIL.PCOptimizer.1!c
Elasticmalicious (high confidence)
DrWebProgram.Unwanted.1152
MicroWorld-eScanAdware.Generic.1783751
FireEyeAdware.Generic.1783751
CAT-QuickHealRisktool.NSIS.Pcoptimizer.A
McAfeeArtemis!1414BE7A6E80
CylanceUnsafe
ZillyaDownloader.Generic.Win32.4739
SangforTrojan.Win32.Agent.aa
K7AntiVirusAdware ( 004bd8f61 )
K7GWAdware ( 004bd8f61 )
Cybereasonmalicious.a6e80c
CyrenW32/Trojan.GHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MyPCBackup.D potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:RiskTool.MSIL.PCOptimizer.b
BitDefenderAdware.Generic.1783751
NANO-AntivirusRiskware.Win32.MyPCBackup.enqtct
ViRobotAdware.Mypcbackup.2152472
AvastWin32:Adware-gen [Adw]
TencentMsil.Risk.Pcoptimizer.Duwa
SophosGeneric PUA JN (PUA)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GAQ22
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
EmsisoftApplication.PCBackOpt (A)
GDataAdware.Generic.1783751
eGambitGeneric.Malware
AviraHEUR/AGEN.1220205
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwNS.6EAF
MicrosoftTrojan:Win32/Occamy.CE2
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.BundleInstaller.R194324
ALYacAdware.Generic.1783751
VBA32CIL.HeapOverride.Heur
MalwarebytesMalware.AI.4291746924
TrendMicro-HouseCallTROJ_GEN.R002H0CK321
YandexRiskware.PCOptimizer!HNp6QnAjbEw
SentinelOneStatic AI – Malicious PE
FortinetRiskware/PCOptimizer
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Malware.AI.4291746924?

Malware.AI.4291746924 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment