Malware

Malware.AI.4174443386 (file analysis)

Malware Removal

The Malware.AI.4174443386 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4174443386 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4174443386?


File Info:

name: 2CF8DD8DBAA97B8FB9DC.mlw
path: /opt/CAPEv2/storage/binaries/e5901d6c66cd16e0914672708d95983d0182273b64faaaee8484ac323fe35633
crc32: 8D9F6238
md5: 2cf8dd8dbaa97b8fb9dc38eb2d17f8f2
sha1: 71a323a807b30d7295c91ce3537fd8213dae643b
sha256: e5901d6c66cd16e0914672708d95983d0182273b64faaaee8484ac323fe35633
sha512: 6cc04b80cb60bab53be381aa997601cdaddeefbfd24e7f7f59ba4727969cd6e7215ef8f9b0c0af09783a987353428d6ad8dd48529b98d79366bb0c43a7b3f352
ssdeep: 3072:4MnfANNJGpZlSMirTnjPPWaeCojskegYqZHVrbcu1Rnzugc2h:4MfaNJgDUrTrYHj6KVrbL1RzW2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2045A1033E4C43AE26A163549BD4666C775B8271A21DECF7FC82EAE1FE53D187103A6
sha3_384: 860dd59161ddce022b1c019e5e90fa422fd47ee2fa5899ed2d586ff19317348c546d17f2a017f167ee1a65726d52d083
ep_bytes: e826600000e995feffffff35b8c24100
timestamp: 2017-01-20 06:38:53

Version Info:

CompanyName: TODO: <公司名
FileDescription: 1.0.0.3
FileVersion: 1.0.0.3
InternalName: ExeRes.exe
LegalCopyright: Copyright (C) 2016
OriginalFilename: ExeRes.exe
ProductName: TODO:
ProductVersion: 1.0.0.3
Translation: 0x0804 0x04b0

Malware.AI.4174443386 also known as:

BkavW32.Common.8CFC6E1E
LionicTrojan.Win32.Presenoker.4!c
MicroWorld-eScanDropped:Generic.Malware.SYd.4577EA75
SkyhighBehavesLike.Win32.Infected.ch
McAfeeArtemis!2CF8DD8DBAA9
MalwarebytesMalware.AI.4174443386
VIPREDropped:Generic.Malware.SYd.4577EA75
SangforDropper.Win32.Presenoker.V7ve
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitGeneric.Malware.SYd.4577EA75
BitDefenderThetaAI:Packer.1CBC36A71F
APEXMalicious
BitDefenderDropped:Generic.Malware.SYd.4577EA75
AvastWin32:Malware-gen
EmsisoftDropped:Generic.Malware.SYd.4577EA75 (B)
FireEyeGeneric.mg.2cf8dd8dbaa97b8f
MAXmalware (ai score=100)
Kingsoftmalware.kb.a.895
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDropped:Generic.Malware.SYd.4577EA75
AhnLab-V3Malware/Win32.Generic.C2704192
ALYacDropped:Generic.Malware.SYd.4577EA75
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09EE23
RisingPUF.Presenoker!8.F608 (TFE:5:m0JWPsNBopH)
MaxSecureTrojan.Malware.208522788.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.807b30
DeepInstinctMALICIOUS

How to remove Malware.AI.4174443386?

Malware.AI.4174443386 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment