Malware

Should I remove “Malware.AI.4147494767”?

Malware Removal

The Malware.AI.4147494767 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4147494767 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Malware.AI.4147494767?


File Info:

name: 87280E8011670C7E5322.mlw
path: /opt/CAPEv2/storage/binaries/743d24f78a9f85ebc8b17b0fb9346d9dded06acdd0e6e1d919537f11e25ebf90
crc32: C5D72164
md5: 87280e8011670c7e532219b7a83bcb53
sha1: 5d3a7fe25e9cffa9c1addce557a2a9161c4863ef
sha256: 743d24f78a9f85ebc8b17b0fb9346d9dded06acdd0e6e1d919537f11e25ebf90
sha512: 078873933b794f4252212362ca2ff24a7369dfcda2ae78d60bb479122c4db287268110300dd9d6e34a1ee7d5588c8672aa51cb27ffb84d89d85b8c3925e43632
ssdeep: 196608:8pylm3jjEjFVwNH0SRlRI2BOobN7BQdol6i:8f3jYxm0Ed5bbQdo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC66334B98402B3AD07035F28CFB575760B73C610820946AF96C399D6B761A7DC3EBE9
sha3_384: 23f4b02fd79d39b4436fcdcb97e2f912c45e771a27e5a411fa9c4e17886f9343880a37f2faec28228e68dcae6d622e0c
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Synfr
FileDescription: Effector Saver 9
FileVersion: 2.9.0.7
LegalCopyright:
Translation: 0x0409 0x04e4

Malware.AI.4147494767 also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.143680
FireEyeGen:Variant.Cerbu.143680
ALYacGen:Variant.Cerbu.143680
CylanceUnsafe
SangforTrojan.Win32.Ekstak.amedq
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.1612d605
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
TrendMicro-HouseCallTROJ_GEN.R002H0DET22
ClamAVWin.Adware.Cerbu-9946114-0
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderGen:Variant.Cerbu.143680
CynetMalicious (score: 100)
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Mqil
Ad-AwareGen:Variant.Cerbu.143680
EmsisoftGen:Variant.Cerbu.143680 (B)
DrWebTrojan.MulDrop20.6345
VIPREGen:Variant.Cerbu.143680
McAfee-GW-EditionArtemis!Trojan
JiangminTrojan.Ekstak.bxpk
AviraTR/Drop.Agent.tuhpa
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Backdoor.Bodelph.U0CUDV
AhnLab-V3Adware/Win.Generic.R495687
McAfeeArtemis!87280E801167
MalwarebytesMalware.AI.4147494767
YandexTrojan.Ekstak!bAFJp4S3VY4
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4147494767?

Malware.AI.4147494767 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment