Malware

Malware.AI.4074839274 removal tips

Malware Removal

The Malware.AI.4074839274 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4074839274 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4074839274?


File Info:

name: 3AC400A8A2FF687F215A.mlw
path: /opt/CAPEv2/storage/binaries/05e2eea9763f9c1b906cc623ddc54ae8eda08f5de577d298dc652aac41840592
crc32: B136CCA0
md5: 3ac400a8a2ff687f215a13af35995710
sha1: 82d9483c223e267efc507aede6a24d5f9684f692
sha256: 05e2eea9763f9c1b906cc623ddc54ae8eda08f5de577d298dc652aac41840592
sha512: e4e80e7aa9f9b28c85c8a3229ed90334270c1f799422879c79ee52d37eae04210a41fffaed31fe71f0e8fbf67ba8db7ee09dfdfb18d03be6fc5f952d07fcd2db
ssdeep: 1536:yvqPRfqCPUJd17cyMVHfIGWmlsr9A2EqrAhrBDlyJsfoLmstfjlzh7cBEvMNnouJ:3PRnVH1lsr9AWAhB6sf8ZtFcSvSouteE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F973F105BB8A5F4ACCDEE1719C0D939E9C64FC348DB8826F9588323E9770766192C48D
sha3_384: fcfc3d083e87c83a296fc9029e583261cb1fdddf962717b4adf0ad742620749f322112559f00377ee4f2b9abc1127aab
ep_bytes: 60be00a042008dbe0070fdff5789e58d
timestamp: 2010-11-19 00:46:48

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
LegalCopyright: TODO: (c) . All rights reserved.
InternalName: IEKeyword_EXE.exe
OriginalFilename: IEKeyword_EXE.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0412 0x03b5

Malware.AI.4074839274 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Fragtor.214072
FireEyeGeneric.mg.3ac400a8a2ff687f
CAT-QuickHealTrojanDownloader.Fosniw.C5
McAfeeGeneric Malware.u!pec
Cylanceunsafe
ZillyaDownloader.Fosniw.Win32.74314
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059c5251 )
AlibabaTrojanDownloader:Win32/Fosniw.6915b27a
K7GWTrojan ( 0059c5251 )
Cybereasonmalicious.8a2ff6
BitDefenderThetaAI:Packer.2D4D20631F
VirITTrojan.Win32.Generic.MC
CyrenW32/Fosniw.E.gen!Eldorado
SymantecDownloader
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Fosniw.AU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Fosniw-2
KasperskyVHO:Trojan-Ransom.Win32.Convagent.gen
BitDefenderGen:Variant.Fragtor.214072
NANO-AntivirusRiskware.Win32.IEKeyword.ecjffo
AvastWin32:DropperX-gen [Drp]
TencentWin32.AdWare.Generic.Pzfl
EmsisoftGen:Variant.Fragtor.214072 (B)
BaiduWin32.Trojan-Downloader.Fosniw.a
F-SecureTrojan.TR/Agent.233472.31
DrWebTrojan.DownLoader21.45702
VIPREGen:Variant.Fragtor.214072
TrendMicroTROJ_AGENT_008606.TOMB
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
Trapminemalicious.high.ml.score
SophosMal/Behav-044
IkarusGen.Variant.Cudos
GDataGen:Variant.Fragtor.214072
WebrootW32.Downloader.Fosniw.C
GoogleDetected
AviraTR/Agent.233472.31
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Agent.FNA@3os0mb
ArcabitTrojan.Fragtor.D34438
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
MicrosoftTrojanDownloader:Win32/Fosniw.C
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Winsoft31.Gen
VBA32BScope.Trojan.Occamy
ALYacGen:Variant.Fragtor.214072
MAXmalware (ai score=100)
MalwarebytesMalware.AI.4074839274
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_AGENT_008606.TOMB
RisingTrojan.IEKeyword!1.6A27 (CLOUD)
YandexTrojan.GenAsa!0ZWgMw0FVW4
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dloader.ANW!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4074839274?

Malware.AI.4074839274 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment