Malware

Should I remove “Malware.AI.422939629”?

Malware Removal

The Malware.AI.422939629 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.422939629 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Created a process from a suspicious location
  • Attempts to modify Windows Defender using PowerShell
  • Anomalous binary characteristics

How to determine Malware.AI.422939629?


File Info:

name: 3718F848A413D3F1C728.mlw
path: /opt/CAPEv2/storage/binaries/82187ddf22f5c705eb6577731f6116785476f1df7690e9dd93368336f8a5ebc6
crc32: F669C949
md5: 3718f848a413d3f1c728dbb642245fed
sha1: ccba003418f8d57efb9b6b2bde71d913136ad911
sha256: 82187ddf22f5c705eb6577731f6116785476f1df7690e9dd93368336f8a5ebc6
sha512: 3479f7ad97bd02fe9dda2763f9cb1d2390553e2d80a7946336e4d1dc690ecc3caf7f80761bf75f5cb9cb43900b25ef84a5beed60feb1b49a4848af7700087524
ssdeep: 49152:tdFlFkXCt/BFEYwFzd7KnM6Z7wTdYLuVWMlFbccgOkcFrjBAJ7:tdF8XCt/BFEYwFzd7KnM6Z71Url+1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F95096CF6C268F8E61B7170810BF77B8ED469348020EDBBEF55DA86B03316A350B565
sha3_384: 020246ee696df50c3debfd346a6f9c237df07aabe474cefe7ac29d7dc0d9717a70dd5868c26e5830cc33ba1dd7f3babc
ep_bytes: c705b0e15b0001000000e9b1fcffff90
timestamp: 2022-07-10 22:03:10

Version Info:

0: [No Data]

Malware.AI.422939629 also known as:

LionicTrojan.Win32.Fsysna.4!c
MicroWorld-eScanGen:Variant.Fragtor.116081
FireEyeGen:Variant.Fragtor.116081
McAfeeArtemis!3718F848A413
CylanceUnsafe
SangforTrojan.Win32.Agent.Vicl
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanSpy:Win32/Stealer.02cbb1dc
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.418f8d
ArcabitTrojan.Fragtor.D1C571
BitDefenderThetaGen:NN.ZexaF.34786.8PX@ae4@VOdi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H07GB22
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.ceti
BitDefenderGen:Variant.Fragtor.116081
Ad-AwareGen:Variant.Fragtor.116081
EmsisoftGen:Variant.Jaik.84875 (B)
VIPREGen:Variant.Jaik.84875
McAfee-GW-EditionBehavesLike.Win32.Worm.th
AviraTR/Spy.Stealer.btkbu
Antiy-AVLTrojan/Generic.ASMalwS.3026
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fragtor.116081
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C5197752
VBA32BScope.TrojanPSW.RedLine
ALYacGen:Variant.Jaik.84875
MAXmalware (ai score=83)
MalwarebytesMalware.AI.422939629
AvastWin32:MalOb-IJ [Cryp]
RisingBackdoor.Agent!8.C5D (TFE:dGZlOgW7YKPy3674VQ)
FortinetW32/PossibleThreat
AVGWin32:MalOb-IJ [Cryp]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.422939629?

Malware.AI.422939629 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment