Malware

Malware.AI.4071197022 removal guide

Malware Removal

The Malware.AI.4071197022 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4071197022 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4071197022?


File Info:

name: 4C7BA03066F8AF382914.mlw
path: /opt/CAPEv2/storage/binaries/ab6329bddbec19c06a223d76e589495d075607f384b81203a5a17c98b8ead110
crc32: F3D4FF61
md5: 4c7ba03066f8af38291412fac1930a68
sha1: 3a661c77cb15c1682ac48da61a652eac64a02199
sha256: ab6329bddbec19c06a223d76e589495d075607f384b81203a5a17c98b8ead110
sha512: b30efb82df2067213acee5060a5aecdd1f3edefc17c2f1e3f525f8502c0908858cceae3b8c22bdb3ea3d47786c6b14fdafbac27338715dfe039f6c14c89639ab
ssdeep: 24576:MpglfUKKDgXkvxpwe7hpo0EkQ0WU4NVQPMhHymzdWS/Ni/Gw4RxMdiMxj67Via0S:HYJJOEhv20pwsMhVBX/NigRSL67Vi7WP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173850280BED8CCACF5650439CB605A5CF96CFC23BFA945DE23509A1BC9E10C2593B5AD
sha3_384: 0f4a03faab997213004ccb071351716cddcf10e45b16443deac689f14504fc217b77dfd499707352c5276bc99792bb04
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2021-11-15 21:24:04

Version Info:

0: [No Data]

Malware.AI.4071197022 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Fragtor.47730
FireEyeGeneric.mg.4c7ba03066f8af38
CAT-QuickHealW32.BrowserAssistant.B7
McAfeeArtemis!4C7BA03066F8
ZillyaTrojan.Blocker.Win32.86193
SangforTrojan.Win32.Agent.xanfim
K7AntiVirusTrojan ( 0058e2a81 )
K7GWTrojan ( 0058e2a81 )
Cybereasonmalicious.066f8a
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.ERBU
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Agent.xanfim
BitDefenderGen:Variant.Fragtor.47730
TencentWin32.Trojan.Agent.Pezz
Ad-AwareGen:Variant.Fragtor.47730
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DBC22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Fragtor.47730 (B)
Paloaltogeneric.ml
GDataWin32.Trojan.PSE.JAWRU8
GridinsoftRansom.Win32.Blocker.sa
MicrosoftRansom:Win32/CerberCrypt.PB!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R457234
VBA32BScope.Trojan.Meterpreter
ALYacGen:Variant.Fragtor.47730
MAXmalware (ai score=85)
MalwarebytesMalware.AI.4071197022
TrendMicro-HouseCallTROJ_GEN.R002C0DBC22
RisingTrojan.BunituCrypt!8.123D8 (TFE:dGZlOgXBFSLPFgjCKQ)
IkarusTrojan.Win32.Crypt
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4071197022?

Malware.AI.4071197022 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment