Malware

Malware.AI.4293039742 removal

Malware Removal

The Malware.AI.4293039742 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4293039742 virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.4293039742?


File Info:

name: 51687B0CBEE9ED781819.mlw
path: /opt/CAPEv2/storage/binaries/6f1ce745b5a1cc39222b9ff282cef62d1fe95df299706d6dc1c0de04beaf1fd6
crc32: C830757E
md5: 51687b0cbee9ed781819d4fdcb9bcced
sha1: e1ddf4be9af9ebf76819d0b1303ef46ddb977fa0
sha256: 6f1ce745b5a1cc39222b9ff282cef62d1fe95df299706d6dc1c0de04beaf1fd6
sha512: 46defe5f0cdc5d40dedb6aedb98770b6568f91059bbb57562601e478c8cb0f6106b09809c550571c521756cbbc06378994afe929964edd499ee4a5c7b8cfe820
ssdeep: 98304:4XfDGH3PRM4qdoqQv3WIQXt2F3tRsAaNMWA/XepCK3kPs63gf3C:mfD+fRM+fv3WzqtR4DA211y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1010633162E31D190CCB4B435AF73CB6D197B4DF036F289D2FE6758A94AC61B50018ABE
sha3_384: 0931d823e62f6e2dee95640d1b2660baabf05c0ae9e9fef0b7ad35d657e07f5c78d330755f7eb6a274a5a7ca2fa8338a
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:27

Version Info:

CompanyName: 360.cn
FileDescription:
FileVersion: 2014.06.17.163352
InternalName: 360sd.exe
LegalCopyright:
OriginalFilename: 360sd.exe
ProductName: fly
ProductVersion: 2014.06.17.163352
Translation: 0x0804 0x03a8

Malware.AI.4293039742 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.39570837
FireEyeTrojan.GenericKD.39570837
CAT-QuickHealHacktool.Flystudio.16558
ALYacTrojan.GenericKD.39570837
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/QQWare.31e85f8a
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
VirITTrojan.Win32.Agent4.BZXP
CyrenW32/S-776111c5!Eldorado
ESET-NOD32a variant of Win32/QQWare.AT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Delf.gen
BitDefenderTrojan.GenericKD.39570837
NANO-AntivirusTrojan.Win32.QQWare.dbyyff
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.39570837
SophosMal/Generic-S
DrWebTrojan.MulDrop6.49124
ZillyaDownloader.Delf.Win32.62826
TrendMicroTROJ_GEN.R002C0PDR22
McAfee-GW-EditionPUP-XEC-GR
EmsisoftTrojan.GenericKD.39570837 (B)
IkarusBackdoor.Win32.Hupigon
JiangminTrojan/Mepaow.bve
AviraTR/QQTen.cpdee
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Generic.D25BCD95
ViRobotTrojan.Win32.Z.Qqware.3696017
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!51687B0CBEE9
MAXmalware (ai score=84)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.4293039742
TrendMicro-HouseCallTROJ_GEN.R002C0PDR22
RisingPUA.GoodPic!8.1F06 (CLOUD)
FortinetRiskware/FlyStudio
BitDefenderThetaGen:NN.ZexaF.34712.1mKfaWtjgnjb
AVGWin32:Malware-gen
Cybereasonmalicious.e9af9e
PandaTrj/CI.A

How to remove Malware.AI.4293039742?

Malware.AI.4293039742 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment