Malware

Should I remove “Malware.AI.4247624900”?

Malware Removal

The Malware.AI.4247624900 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4247624900 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

Related domains:

wpad.local-net
flingtrainer.com

How to determine Malware.AI.4247624900?


File Info:

name: 8383798E5F7ABB936EB2.mlw
path: /opt/CAPEv2/storage/binaries/8f4256fe3165b266d7cc7ce35bc3195ab93488f72ceed2995d372ca27625d53f
crc32: C62EC1EC
md5: 8383798e5f7abb936eb2e04c25bdeaa1
sha1: e587e222846874cd6c8ec0797bc8c1b0e03ac147
sha256: 8f4256fe3165b266d7cc7ce35bc3195ab93488f72ceed2995d372ca27625d53f
sha512: a2ac52702313f44eed583b0af754477ce96af3b4cf1ae5e725a01394d013c58b7a06e9bd2b9c0ec96ab58b73ca211b3263ab99b6b517d8060274cb384bf758ea
ssdeep: 24576:z50Gn70Q/I4BxsGeWl/xzykjAmMiUuDSlhJ:bF/F71eMxz/xMiyh
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1DE25AE5AA79544F8D177D13AC9A28A56F7B274061B708BDF13A0436F1F632E08F7A321
sha3_384: c416bf33cf6db2f3872bf31cf0b570cee1dc3e371bf809b026b785b9f9b80b6963349b597ce22055760f4620bfcf820f
ep_bytes: 4883ec28e86b0900004883c428e97afe
timestamp: 2020-09-15 23:36:03

Version Info:

CompanyName: 3DMGAME
FileDescription: Mortal Kombat 11 v1.0-v20200915 Plus 12 Trainer
FileVersion: 1.0.0.0
InternalName: Mortal Kombat 11 v1.0-v20200915 Plus 12 Trainer
LegalCopyright: FLiNG Copyright (C) 2020
OriginalFilename: Mortal Kombat 11 v1.0-v20200915 Plus 12 Trainer.exe
ProductName: Mortal Kombat 11 v1.0-v20200915 Plus 12 Trainer
ProductVersion: 1.0.642.6
Translation: 0x0000 0x04b0

Malware.AI.4247624900 also known as:

LionicRiskware.Win32.Generic.1!c
CylanceUnsafe
SangforPUP.Win32.Presenoker.mt
K7GWUnwanted-Program ( 0055d9971 )
K7AntiVirusUnwanted-Program ( 0055d9971 )
CyrenW64/Trojan.SHTF-2416
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win64/GameHack.CT potentially unsafe
Sophos3DMGAME Trainer (PUA)
McAfee-GW-EditionBehavesLike.Win64.AdSnare.dc
GridinsoftRansom.Win64.Gen.sa
ViRobotAdware.GameHack.1009664
MicrosoftPUA:Win32/Presenoker
AhnLab-V3Unwanted/Win64.GameCheat.C4200600
McAfeeRDN/Generic.dx
MalwarebytesMalware.AI.4247624900
TrendMicro-HouseCallTROJ_GEN.R002H06JU21
YandexTrojan.Igent.bUPKUh.25
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/GameHack
PandaPUP/Generic

How to remove Malware.AI.4247624900?

Malware.AI.4247624900 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment