Malware

Malware.AI.4220808002 (file analysis)

Malware Removal

The Malware.AI.4220808002 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4220808002 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools

How to determine Malware.AI.4220808002?


File Info:

name: 53B0398EE99B58841F5F.mlw
path: /opt/CAPEv2/storage/binaries/4867ad7e5caf98e2fbb86f96cb92cd4efa2bd725f90cc25c659aa08b442844a1
crc32: 90FC0D99
md5: 53b0398ee99b58841f5f41bd8755026a
sha1: 7f151a27fdfd32c3e88ed7c3205226b4b753ce56
sha256: 4867ad7e5caf98e2fbb86f96cb92cd4efa2bd725f90cc25c659aa08b442844a1
sha512: bb628ed5c9aea983ddbe7ec10d3af6ff85b2cbed74973bba4c2ac2729589bfafc90c5812f7d6d7c85f2304b8b571b7f4682cdcb3dabaf0cee02a2d8dd078623c
ssdeep: 768:ou5SJuJk7p99ZUM9S05cYokCcqoGaohK9C8cxBzBjFBZ7ZQa:r5YD4M9S05CkCHRhdFzea
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D433CF33F2ACFD28D0891E766A7773403285BB0259AA7B16DD43750BD930191AD6CDD3
sha3_384: 93113d9ec479591bf1d46b07363ffbbbb0f321027fd8d46e5843c62b87e9813a15399361f9e1582a78fac173922618ff
ep_bytes: 60be00e040008dbe0030ffff5783cdff
timestamp: 2012-12-25 03:04:47

Version Info:

CompanyName: 河北博才网
FileDescription: 将河北博才网快捷方式放置桌面,方便用户直达网站
FileVersion: 1.3.3.0
InternalName: web_hbrc
LegalCopyright: 河北博才人力资源服务有限公司
OriginalFilename: web_hbrc.exe
ProductName: 快捷方式打开河北博才网
ProductVersion: 1.3.3.0
Translation: 0x0804 0x04b0

Malware.AI.4220808002 also known as:

LionicTrojan.Multi.Generic.4!c
FireEyeGeneric.mg.53b0398ee99b5884
MalwarebytesMalware.AI.4220808002
SangforRiskware.Win32.Agent.ky
K7AntiVirusRiskware ( 00584baa1 )
AlibabaWorm:Win32/Autorun.b1262093
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.7fdfd3
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PAA22
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AvastWin32:Malware-gen
ComodoTrojWare.Win32.VB.YNB@4x8any
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PAA22
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
Trapminemalicious.moderate.ml.score
SophosMal/Generic-R + Mal/Emogen-F
IkarusTrojan.Win32.VB
WebrootW32.Gen.BT
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.2A5096B
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/Dynamer!ac
CynetMalicious (score: 100)
McAfeeArtemis!53B0398EE99B
VBA32Trojan.Dynamer
APEXMalicious
RisingTrojan.Dynamer!8.3A0 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Emogen.F!worm
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.4220808002?

Malware.AI.4220808002 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment