Malware

Malware.AI.4204462979 (file analysis)

Malware Removal

The Malware.AI.4204462979 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4204462979 virus can do?

  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

Related domains:

wpad.local-net
meron.kanoga-apps.com

How to determine Malware.AI.4204462979?


File Info:

name: BE377F7E1F662E2AD165.mlw
path: /opt/CAPEv2/storage/binaries/ac55907ec42c71bc7ae6c7fcd043df6bc55ddf3412be4f0cea348d495631659d
crc32: 3B71759E
md5: be377f7e1f662e2ad165624a9833a81d
sha1: ace64b3a1db1c350bb9e80ffff5dad1b5577975b
sha256: ac55907ec42c71bc7ae6c7fcd043df6bc55ddf3412be4f0cea348d495631659d
sha512: 5a794a32da9c9855363ec9e3f6f1d0fd4404401ca7a3b4acb2f2ad69926c5b632baec172bb08bbb0b6519416b4a7b9b764a105e86e10a43be3be4d97bfba31f1
ssdeep: 1536:W04f1SMHjZ0k/tB1g//I0DuoxbxAHscygjf3B/MQJSHEsuxibxXZTa8rq5y8:of1BDZ0kVB67Duw9AMc7/n6uibxJ0y8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166649E5A79D9D8B3DA618570076BE3A9BB5842440349870B17C57CBC398BF820E2E5FB
sha3_384: da29e282c6c4816db9f4da3fc3c0b670ee9fa24533cc06d55f6f3802fa985dd6454134d25a3977ef73c8b760a45a62e4
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2020-08-01 02:44:50

Version Info:

FileVersion: 2.1.7.873
ProductVersion: 2.1.49.590
Translation: 0x0409 0x04e4

Malware.AI.4204462979 also known as:

LionicTrojan.Win32.Adload.a!c
MicroWorld-eScanTrojan.GenericKD.47480381
FireEyeTrojan.GenericKD.47480381
CAT-QuickHealTrojanDownloader.Adload
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 0058ab511 )
AlibabaAdWare:Win32/AdLoad.8e8819a6
K7GWTrojan-Downloader ( 0058ab511 )
CyrenW32/Adload.GF.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/TrojanDownloader.Agent.NZR
TrendMicro-HouseCallTROJ_GEN.R03BC0PL221
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
BitDefenderTrojan.GenericKD.47480381
AvastNSIS:DropperX-gen [Drp]
TencentNsis.Trojan-downloader.Agent.Pgwl
Ad-AwareTrojan.GenericKD.47480381
EmsisoftTrojan.GenericKD.47480381 (B)
DrWebAdware.Downware.20015
TrendMicroTROJ_GEN.R03BC0PL221
McAfee-GW-EditionRDN/Generic Downloader.x
SophosMal/Generic-S
GDataTrojan.GenericKD.47480381
WebrootW32.Dropper.Gen
AviraTR/Dldr.Agent.bfhiu
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D47E3D
ViRobotTrojan.Win32.Z.Agent.325434
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Dropper/Win.DropperX-gen.C4785887
VBA32suspected of Trojan.Downloader.gen
ALYacTrojan.GenericKD.47480381
MalwarebytesMalware.AI.4204462979
FortinetNSIS/Agent.NZR!tr.dldr
AVGNSIS:DropperX-gen [Drp]
PandaTrj/CI.A

How to remove Malware.AI.4204462979?

Malware.AI.4204462979 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment