Malware

Malware.AI.4140318578 removal guide

Malware Removal

The Malware.AI.4140318578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4140318578 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the IcedID malware family
  • Creates a copy of itself

Related domains:

importhe.com
coastleme.biz
desided.biz
cypruns.com

How to determine Malware.AI.4140318578?


File Info:

name: 7E86156C1FA43022F444.mlw
path: /opt/CAPEv2/storage/binaries/22d2e277727dc2416d8d8b6fc25b7ed463a4b8af8b4e871f825c3e56f7265308
crc32: A43C3320
md5: 7e86156c1fa43022f444c1be9167e393
sha1: 99cd2c43973de23b7c68ca934ee79d8f36bedbdc
sha256: 22d2e277727dc2416d8d8b6fc25b7ed463a4b8af8b4e871f825c3e56f7265308
sha512: 97a247624eaf7af8c289ade59f87bfa5872e38ed6cd0215cbb4a82bb1599d4ad645614dccf36d9ff7d1ec2fc1b960dd5bd38a55dcf679f577d925907d80e6ab1
ssdeep: 6144:SszieE4sd6vN2xeFyv9iMmHSu9OcCRPrbpc+spYfnQ4Af:FVt69iMmHp7KPrbpNBle
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179749D627A40C823E3D132748F54E3795B25BE9D2E3686037AF47D6FBA6D3934D28211
sha3_384: a0e56e7c35b7dc91be7801194ea08a8d7240ba367430c1db6bff49383e49c668db05fe4bdeb6796edca23bc2e67f012c
ep_bytes: e8532b0000e989feffff8bff558bec83
timestamp: 2012-11-06 10:14:17

Version Info:

CompanyName: Precision Development Dear
FileDescription: Pushsun
FileVersion: 10.1.63.38
InternalName: Pushsun
LegalCopyright: Copyright © 2008- 2012 Precision Development Dear
LegalTrademarks: Pushsun
ProductVersion: 10.1.63.38
OriginalFilename: littlekeep.exe
ProductName: Pushsun
Translation: 0x0409 0x04b0

Malware.AI.4140318578 also known as:

LionicTrojan.Win32.IcedID.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.53
FireEyeGeneric.mg.7e86156c1fa43022
ALYacGen:Heur.Mint.Zard.53
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005409ff1 )
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 005409ff1 )
Cybereasonmalicious.c1fa43
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GNPE
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.53
NANO-AntivirusTrojan.Win32.IcedID.fkbhri
AvastWin32:Malware-gen
RisingTrojan.Generic@ML.92 (RDML:2fDG7jn1wASa2i698N+w+w)
Ad-AwareGen:Heur.Mint.Zard.53
TACHYONTrojan/W32.Agent.364032.GG
SophosMal/Generic-S
ComodoMalware@#1b7rub8o0sbxk
DrWebTrojan.IcedID.15
ZillyaTrojan.IcedID.Win32.52
TrendMicroTrojanSpy.Win32.URSNIF.SMKA0.hp
McAfee-GW-EditionUrsnif-FQLY!7E86156C1FA4
EmsisoftGen:Heur.Mint.Zard.53 (B)
IkarusTrojan.Win32.Crypt
GDataGen:Heur.Mint.Zard.53
JiangminTrojan.Banker.IcedID.db
AviraHEUR/AGEN.1124572
GridinsoftRansom.Win32.Skeeyah.sa
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Trojanspy.C2818539
McAfeeUrsnif-FQLY!7E86156C1FA4
MAXmalware (ai score=100)
VBA32TrojanBanker.IcedID
MalwarebytesMalware.AI.4140318578
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMKA0.hp
TencentMalware.Win32.Gencirc.10cce4db
YandexTrojan.PWS.IcedID!gYsNQyXtitU
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GMLM!tr
BitDefenderThetaGen:NN.ZexaF.34294.wq0@aijgKzdi
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4140318578?

Malware.AI.4140318578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment