Malware

Malware.AI.4221983842 removal guide

Malware Removal

The Malware.AI.4221983842 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4221983842 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Malware.AI.4221983842?


File Info:

name: FE33518CE3BEF96A1669.mlw
path: /opt/CAPEv2/storage/binaries/8ee09bb93c571ec3cb7247c3cafd8e3674ff4211fa5da15e65f2892430a41c9a
crc32: 4334A416
md5: fe33518ce3bef96a1669e550f579cbf1
sha1: 3fe3defa56f7e390bf5f94ffc709bd028ffeefd4
sha256: 8ee09bb93c571ec3cb7247c3cafd8e3674ff4211fa5da15e65f2892430a41c9a
sha512: febca1259886e7fa43eb11bd17872dcc9b8d4a1c14970386b29d6ea08fce9872243915bee7585cafd1b5e0744f3cd34272ca522b8f1d29623007f41b1c0b18a2
ssdeep: 196608:yVSvh0DEVKcNRSW5+Nu1eLjtkfp5XLZEfgYkDfkCA:yUJ0oVKKgJNwSjQH7ZEYTzA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1476633F172D072B2E511197778C7E06C15533FA60941FA1F31A8BF2A26B638AE41B367
sha3_384: b302684ea1714df6df956335ed962d77cbd6b456121d1ea0a69c27ff8844a6478b71598d89051b4ac13af73a7259cde8
ep_bytes: 558bec83c4cc53565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Novativr Solutions
FileDescription: Disk Cleaner
FileVersion: 6.0.1.4
LegalCopyright:
Translation: 0x0409 0x04e4

Malware.AI.4221983842 also known as:

LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanGen:Variant.Cerbu.147386
ClamAVWin.Malware.Ekstak-9955675-0
FireEyeGen:Variant.Cerbu.147386
McAfeeArtemis!FE33518CE3BE
CylanceUnsafe
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.c8f64ac8
K7GWTrojan ( 005722f11 )
CyrenW32/Ekstak.CG.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Cerbu.147386
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Ekstak.Xdkl
Ad-AwareGen:Variant.Cerbu.147386
EmsisoftGen:Variant.Cerbu.147386 (B)
F-SecureHeuristic.HEUR/AGEN.1250837
DrWebTrojan.DownLoader45.11553
VIPREGen:Variant.Cerbu.147386
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.QO9NQV
JiangminTrojanDropper.Inokrypt.b
AviraHEUR/AGEN.1250837
ArcabitTrojan.Cerbu.D23FBA
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Adware/Win.Adware-gen.R503210
Acronissuspicious
ALYacGen:Variant.Cerbu.147386
MAXmalware (ai score=83)
MalwarebytesMalware.AI.4221983842
TrendMicro-HouseCallTROJ_GEN.R002H0DG922
YandexTrojan.Ekstak!C2mQ8EizjuI
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr.dldr
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4221983842?

Malware.AI.4221983842 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment