Malware

Malware.AI.4217716228 information

Malware Removal

The Malware.AI.4217716228 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4217716228 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Malware.AI.4217716228?


File Info:

name: 74E9902B20A684E37D1F.mlw
path: /opt/CAPEv2/storage/binaries/425ff0835922cb3826e85572dd1c2bc95cf2846786327ec6d351deefe2ef44ef
crc32: 19AF4C42
md5: 74e9902b20a684e37d1f6669733d1dda
sha1: 36882332ac97f250db1d2ffe4454f34ba6d07119
sha256: 425ff0835922cb3826e85572dd1c2bc95cf2846786327ec6d351deefe2ef44ef
sha512: a2858c08e80f06050b87482292bd50a345ff3788b77f7eca37ca002004afdbeacc8be0ea193f2fc94379e266fbdb34083a05bd1801c6e994252de3923b7bb0ff
ssdeep: 6144:ViG9DTOEEGXWaOhgcJmHeO2GIDU4tuVmaQl5HAKg:MG9HOE7HcJhhU4c+5Hy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14934CF533D5ECDA7C22B0B3550E9D12586784C42FCDA4ED7DF1A7DDAA8B788C300A668
sha3_384: e27d7b710523388fd02c0056c7ac189f56bee671c7f62ff8add571a4eb5123827eda6d3fbaf5de932c9e85195cde639b
ep_bytes: 5589e583ec08c7042402000000ff1590
timestamp: 2022-01-03 09:54:19

Version Info:

0: [No Data]

Malware.AI.4217716228 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.47966455
FireEyeTrojan.GenericKD.47966455
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.GenericKD.47966455
SangforTrojan.Win32.GenericKD.47966455
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.47966455
K7GWTrojan ( 0058dff01 )
K7AntiVirusTrojan ( 0058dff01 )
ArcabitTrojan.Generic.D2DBE8F7
SymantecTrojan.Gen.MBT
ESET-NOD32Python/PSW.Agent.RE
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Multi.Disco.gen
AlibabaTrojanPSW:Win32/Stealer.faf92d3b
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.47966455
SophosMal/Generic-S
DrWebPython.Stealer.415
TrendMicroTROJ_GEN.R002C0PEC22
McAfee-GW-EditionRDN/Generic PWS.y
EmsisoftTrojan.GenericKD.47966455 (B)
AviraTR/PSW.Agent.raken
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.47966455
AhnLab-V3Trojan/Win.PWS.C4946976
ALYacTrojan.GenericKD.47966455
MalwarebytesMalware.AI.4217716228
TrendMicro-HouseCallTROJ_GEN.R002C0PEC22
IkarusTrojan.Python.Psw
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Agent.RE!tr
AVGWin32:Trojan-gen

How to remove Malware.AI.4217716228?

Malware.AI.4217716228 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment