Malware

What is “Malware.AI.4072247493”?

Malware Removal

The Malware.AI.4072247493 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4072247493 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Malware.AI.4072247493?


File Info:

name: 53C24CA7A05F4F59B457.mlw
path: /opt/CAPEv2/storage/binaries/901fec94d546b5f713060c65c284dc29760b72e8d967aa7cd692074e35557398
crc32: 606B94F1
md5: 53c24ca7a05f4f59b45709e4c3d16883
sha1: 07134c341ccc80570ddfb88cc72b1f526cfe7503
sha256: 901fec94d546b5f713060c65c284dc29760b72e8d967aa7cd692074e35557398
sha512: 4855073717e737f7625704600db1b5485128820dca0767a4c393c0a2ac059d062552700fd5041abbee8433d7b9364edadf3cfa281ec0db159a0df5a316a10bd5
ssdeep: 1536:28oof8KN9wpISEeSF6waVuhAySi0lC8rHyY5qjJVojQH:28xfFN9IzSF6vzNgoLqjJVojQH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13CA36C2078C5C8B6E602507309E64FFFE638F4381F271C9763E9E9591E7A580991A3DA
sha3_384: ef6a36c2f417efda6877f2174d8f653dac1a1d0b252db092bb3763d2ea65f24f71d4a8f0e3189dda42b0d1d9d7225038
ep_bytes: 558bec6aff688833410068a0ea400064
timestamp: 2013-03-26 18:17:15

Version Info:

Comments: Helper
CompanyName: Copyrighted ©
FileDescription: Helper File
FileVersion: 1, 0, 0, 0
InternalName: helper
LegalCopyright: Copyright © 2007
LegalTrademarks:
OriginalFilename: jidarmgc.exe
PrivateBuild:
ProductName: helper
ProductVersion: 1, 0, 0, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.4072247493 also known as:

LionicTrojan.Win32.Generic.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.38246
FireEyeGeneric.mg.53c24ca7a05f4f59
CAT-QuickHealTrojan.Skeeyah.9071
McAfeeArtemis!53C24CA7A05F
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusHacktool ( 005287fc1 )
AlibabaBackdoor:Win32/KeyLogger.2af614d4
K7GWHacktool ( 005287fc1 )
Cybereasonmalicious.7a05f4
VirITTrojan.Win32.Generic.PWD
CyrenW32/KeyLogger.Q.gen!Eldorado
ESET-NOD32a variant of Win32/Spy.KeyLogger.ODI
TrendMicro-HouseCallTROJ_GEN.R002C0RFM22
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-701869
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Babar.38246
NANO-AntivirusTrojan.Win32.KeyLogger.cqpghi
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
APEXMalicious
RisingSpyware.Keylogger!1.65EE (CLASSIC)
Ad-AwareGen:Variant.Babar.38246
EmsisoftGen:Variant.Babar.38246 (B)
ComodoTrojWare.Win32.Spy.KeyLogger.ODI@4y3dzi
DrWebTrojan.KeyLogger.20299
ZillyaTrojan.Keylogger.Win32.30012
TrendMicroTROJ_GEN.R002C0RFM22
McAfee-GW-EditionBehavesLike.Win32.Dropper.cm
SophosMal/KeyLog-AF
IkarusTrojan-Spy.Win32.KeyLogger
GDataGen:Variant.Babar.38246
JiangminBackdoor.Generic.aybn
AviraTR/Zusy.10679478
ArcabitTrojan.Babar.D9566
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Backdoor/Win32.Shiz.C207649
VBA32BScope.Trojan.Keyloggerger
ALYacGen:Variant.Babar.38246
MAXmalware (ai score=86)
MalwarebytesMalware.AI.4072247493
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b6ca07
FortinetW32/KeyLogger.AFN!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Malware.AI.4072247493?

Malware.AI.4072247493 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment