Malware

Malware.AI.4292528024 removal tips

Malware Removal

The Malware.AI.4292528024 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4292528024 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the NetWire malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4292528024?


File Info:

name: AAC97CF48EDCD101A781.mlw
path: /opt/CAPEv2/storage/binaries/9b41a85c7f91158ea2412327ab20445420c7291e9d321f307a19a6e9058ed8ca
crc32: 54D1E954
md5: aac97cf48edcd101a781dcf79ac8f09c
sha1: 3fbec564f1c60c1c35a4f471adc734cfd10269c9
sha256: 9b41a85c7f91158ea2412327ab20445420c7291e9d321f307a19a6e9058ed8ca
sha512: a1a6b3b5d1a2be85853dbf9a4751b78108fc9d10585e042e20ebe303249da41dea37870a78c5d4ce552a4268ed6c3656cdef40379d5a4d3c9ad81ad8a7e6248b
ssdeep: 49152:6h+ZkldoPK8YaKW7IF3GvQPdPBYPIy1XvjSED114RM:T2cPK8t7IFWKdZYgy1Wa114R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8C5011273D1D036FFABA2739B6AF2455ABC79250123952F13982D78BD701B1237E263
sha3_384: a3a907e1357f240bbf1679fbea5e73143a669280bb0abbb4608b192a65e4ab87b92d6c3c221d556936ca9c3abad2ff58
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2018-09-03 22:02:30

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.4292528024 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.40448577
FireEyeGeneric.mg.aac97cf48edcd101
SkyhighBehavesLike.Win32.TrojanAitInject.vc
ALYacTrojan.GenericKD.40448577
Cylanceunsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005642691 )
AlibabaTrojan:Win32/Injector.6d97061e
K7GWTrojan ( 005642691 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.Autoit.DKD
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.40448577
NANO-AntivirusTrojan.Win32.Mlw.fhifte
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Qnkl
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1319441
DrWebBackDoor.Siggen2.2517
VIPRETrojan.GenericKD.40448577
TrendMicroTROJ_GEN.R002C0PHR23
EmsisoftTrojan.GenericKD.40448577 (B)
IkarusTrojan.Win32.Injector
VaristW32/AutoIt.VI.gen!Eldorado
AviraHEUR/AGEN.1319441
Kingsoftmalware.kb.a.906
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Generic.D2693241
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.40448577
GoogleDetected
McAfeeArtemis!AAC97CF48EDC
MAXmalware (ai score=100)
VBA32Trojan.Tiggre
MalwarebytesMalware.AI.4292528024
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PHR23
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Cybereasonmalicious.4f1c60
DeepInstinctMALICIOUS

How to remove Malware.AI.4292528024?

Malware.AI.4292528024 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment