Malware

Malware.AI.4184287462 (file analysis)

Malware Removal

The Malware.AI.4184287462 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4184287462 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary

How to determine Malware.AI.4184287462?


File Info:

name: BBAB34C2CEA32B25DA4E.mlw
path: /opt/CAPEv2/storage/binaries/76bbb67a5fcc7a8e60e4bb430443db328d0b538bb96f7055f22f2aad57d9c875
crc32: F4E3CE25
md5: bbab34c2cea32b25da4e386b73e37010
sha1: bda74a166bdaa8fa21a3cc7b13d6f4ee435a2a11
sha256: 76bbb67a5fcc7a8e60e4bb430443db328d0b538bb96f7055f22f2aad57d9c875
sha512: 6ee9a352cd4aaceed457b6fc76dbe2c25161a836db352e97ebeed07c53c0df6c6d1de4dc00b4868c661bc417e5f1a586e8f342a13c5bfc2f44d59e0fba9ef826
ssdeep: 12288:7xfIz7qinOmrmTEEMwHGnjZLNrY5vYvdYbosZOF2hEntE3:7x8smiMEGjBNrWYvdYb0220
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124D41212EFC9197DE7751F3A9E96413BA736BA2A2511C21B72FC0C0C7C233224765B5A
sha3_384: 923f1d98ea6e036c9d69ad24ca9b6c082dc8aacfb37460e9025c6c7e55e827db28a5e144590ec72a30c3aa9cc4180c81
ep_bytes: 558bec83c4c053565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.4184287462 also known as:

LionicTrojan.Win32.Userlogger.4!c
MicroWorld-eScanApplication.Userlogger.A
FireEyeApplication.Userlogger.A
McAfeeArtemis!BBAB34C2CEA3
CylanceUnsafe
AlibabaRiskWare:Win32/UserLogger.2de77fb7
K7GWPassword-Stealer ( 004c4df71 )
K7AntiVirusPassword-Stealer ( 004c4df71 )
VirITMonitor.Win32.UserLogger.A
CyrenW32/Monitor.VOQZ-5797
SymantecSpyware.UserLogger
ESET-NOD32Win32/KeyLogger.UserLogger.A
BitDefenderApplication.Userlogger.A
NANO-AntivirusRiskware.Win32.UserLogger.ftfper
TencentWin32.Risk.Keylogger.Pijz
Ad-AwareApplication.Userlogger.A
EmsisoftApplication.Userlogger.A (B)
ComodoMalware@#1fhjwdg7n3tey
DrWebTrojan.DownLoader2.54114
VIPRETrojan.1
TrendMicroSpyware_TRAK_Userlog.290
McAfee-GW-EditionArtemis!PUP
SophosUserLogger Installer (PUA)
JiangminMonitor.UserLogger.b
WebrootSystem.Monitor.User.Logger
AviraDR/UserLogger.29
KingsoftWin32.Troj.Agent.wq.(kcloud)
MicrosoftTrojan:Win32/Occamy.C76
ViRobotAdware.Userlogger.617343
GDataApplication.Userlogger.A
ALYacApplication.Userlogger.A
VBA32Trojan.Downloader
MalwarebytesMalware.AI.4184287462
TrendMicro-HouseCallSpyware_TRAK_Userlog.290
RisingSpyware.UserLogger!8.52C4 (CLOUD)
YandexRiskware.Monitor!nUGodNVglUM
FortinetRiskware/UserLogger
Cybereasonmalicious.2cea32
PandaTrj/Agent.DPE
MaxSecureTrojan.Malware.1464655.susgen

How to remove Malware.AI.4184287462?

Malware.AI.4184287462 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment