Malware

Malware.AI.4197797303 (file analysis)

Malware Removal

The Malware.AI.4197797303 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4197797303 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4197797303?


File Info:

name: E93B689E2EBC57701668.mlw
path: /opt/CAPEv2/storage/binaries/ea8fcbb9e443d3418915f9272e1e24f34fb0fd898331e7241ecc36d05936108c
crc32: CCDBD196
md5: e93b689e2ebc57701668880044b28b34
sha1: 02b3da2410e2a8eaba3a740cd2d5578af20b008f
sha256: ea8fcbb9e443d3418915f9272e1e24f34fb0fd898331e7241ecc36d05936108c
sha512: eec10c95f7a13fb49469c023070e99afd4539883a3182b01aef093a252e559f4f0a9841a45e1d2bb7070ea70563e63a2f5719f806d413ff4649ea5a5b952f823
ssdeep: 3072:rIFzezhT1hllCRlK7FvGW1YW02bGQgHxJn1MxQgLLnU0vbLUb1BwkRE3:R11JChWxX6Z2xQgPncsF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A314299D7B895FAEE234BCBCC48A41F1339BA4FC76C7F272935CE91499E42645421D20
sha3_384: 70035df53eeaf28a1accdd61fbda131b4ecd12aea704da9d95982392b1c98b8a2cab787109987aa43efb401c31a5cd22
ep_bytes: bf0000000083ec04890c2429c281e801
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.4197797303 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Siggen21.55534
MicroWorld-eScanGen:Variant.Lazy.419762
FireEyeGeneric.mg.e93b689e2ebc5770
SkyhighBehavesLike.Win32.Generic.cm
ALYacGen:Variant.Lazy.419762
MalwarebytesMalware.AI.4197797303
VIPREGen:Variant.Lazy.419762
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004ef0291 )
BitDefenderGen:Variant.Lazy.419762
K7GWTrojan ( 004ef0291 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36792.m0W@a8Xb83m
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.FFM
APEXMalicious
KasperskyTrojan.Win32.Copak.ahelm
NANO-AntivirusTrojan.Win32.Kryptik.kcwkai
RisingTrojan.Injector!1.C865 (CLASSIC)
SophosMal/HckPk-A
F-SecureTrojan.TR/Crypt.Agent.tdumh
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Lazy.419762 (B)
IkarusTrojan.Win32.Injector
GoogleDetected
AviraTR/Crypt.Agent.tdumh
VaristW32/Khalesi.N.gen!Eldorado
Kingsoftmalware.kb.b.972
MicrosoftTrojan:Win32/Injector.RAQ!MTB
ArcabitTrojan.Lazy.D667B2
ZoneAlarmTrojan.Win32.Copak.ahelm
GDataGen:Variant.Lazy.419762
CynetMalicious (score: 100)
McAfeeArtemis!E93B689E2EBC
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/Genetic.gen
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.410e2a
AvastWin32:Evo-gen [Trj]

How to remove Malware.AI.4197797303?

Malware.AI.4197797303 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment