Malware

Malware.AI.403076949 removal instruction

Malware Removal

The Malware.AI.403076949 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.403076949 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Malware.AI.403076949?


File Info:

name: 9BE33C7B7C7490E10C42.mlw
path: /opt/CAPEv2/storage/binaries/4c7651a483a39d25d6a58d7dc1b548900430e4c0dc8ddae38241ac5ad13799f2
crc32: 454313FD
md5: 9be33c7b7c7490e10c4209834cbee2b6
sha1: 7a90d611020c3e861c30520d2c91e47bcd82502c
sha256: 4c7651a483a39d25d6a58d7dc1b548900430e4c0dc8ddae38241ac5ad13799f2
sha512: 50b98600ae499a8e738a534698a408f9289eadca2cf9962931d009969aa757e10e55eeaa149031315245978aeed02252e266454ed380886d3b52de668878f99f
ssdeep: 1536:5NkM25llBCXFSOJfoMqcR0LSBrsn+3i3U:5SllLCXFrbqcRI0rkU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A33E1076ACEDB23DE7B427D44C1DA4907BA66377673E29F6C40725A2E52BE00017A83
sha3_384: 0d39241d1b1cd179f940b5869eb31985e843917a2fe6408e81245ed0146eb7e9707137f31099392c653463e8bab26448
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-22 09:49:22

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ProjectTimCaWinDow
FileVersion: 1.0.0.0
InternalName: ProjectTimCaWinDow.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: ProjectTimCaWinDow.exe
ProductName: ProjectTimCaWinDow
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.403076949 also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.864917
McAfeeRDN/Generic.dx
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
AlibabaTrojanSpy:Win32/Quasar.b3035509
Cybereasonmalicious.1020c3
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.864917
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Bulz.864917
EmsisoftGen:Variant.Bulz.864917 (B)
TrendMicroTROJ_GEN.R067C0PJS21
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
FireEyeGeneric.mg.9be33c7b7c7490e1
SophosGeneric ML PUA (PUA)
IkarusTrojan.Spy.Quasar
MAXmalware (ai score=88)
MicrosoftBackdoor:Win32/Bladabindi!ml
ViRobotTrojan.Win32.Z.Agent.50688.AIN
GDataGen:Variant.Bulz.864917
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4721314
ALYacGen:Variant.Bulz.864917
MalwarebytesMalware.AI.403076949
TrendMicro-HouseCallTROJ_GEN.R067C0PJS21
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetPossibleThreat.PALLAS.H
BitDefenderThetaGen:NN.ZemsilF.34294.dm0@aqfy74e
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.403076949?

Malware.AI.403076949 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment