Malware

Malware.AI.4274392878 information

Malware Removal

The Malware.AI.4274392878 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4274392878 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4274392878?


File Info:

name: BCF367A657300F20285E.mlw
path: /opt/CAPEv2/storage/binaries/7e1faf46c1748ec9f09bf891fc2b17ca377e866066701e436606b98da36e4728
crc32: C67485D6
md5: bcf367a657300f20285efa88611d01d5
sha1: bb7f54f968c4830830619c34e8785b87e82897f0
sha256: 7e1faf46c1748ec9f09bf891fc2b17ca377e866066701e436606b98da36e4728
sha512: 156cdcbe8fd282de6509a87ecae94fd7f557e4b64eafb445424e816da37f8af38c5fff07c7b6e36bec6eacfd7d8367121bd52a72bf144c434cc436de636caaa7
ssdeep: 49152:nfAegLiqLaWbKlLXKi9jHwHU9Xwr6aydzEPDvu5eQOI1pVQ:nfAeciorbY2i9zuUGm6TQO/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FFC5232791088527EC21B3F88411FBB6858F8FC4B971885B6EBC7866F671107ED296DC
sha3_384: 3891e1633803272484cbca3bc57b0fb7a842a5b93a2bcba92ab7f108aba1b89a5c4bd7efded037456364293f143f4e36
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Hatenata Setup
FileVersion:
LegalCopyright: Lomodoruto
ProductName: Hatenata
ProductVersion: 4.8.7
Translation: 0x0000 0x04b0

Malware.AI.4274392878 also known as:

LionicAdware.Win32.DealPly.2!c
MicroWorld-eScanApplication.DealAlpha.2.Gen
FireEyeApplication.DealAlpha.2.Gen
CylanceUnsafe
SangforPUP.Win32.Presenoker.mt
AlibabaAdWare:Win32/InstallCore.7f63302b
CrowdStrikewin/grayware_confidence_100% (D)
CyrenW32/Kryptik.BGE.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/InstallCore.Gen.B potentially unwanted
Kasperskynot-a-virus:AdWare.Win32.DealPly.heur
BitDefenderApplication.DealAlpha.2.Gen
EmsisoftApplication.DealAlpha.2.Gen (B)
ComodoMalware@#1r75vqyljldt
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosInnoMod (PUA)
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1203451
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotAdware.Installcore.2510331
GDataWin32.Application.InstallCore.LX
CynetMalicious (score: 99)
McAfeeArtemis!BCF367A65730
VBA32Adware.DealPly
MalwarebytesMalware.AI.4274392878
RisingPacker.Win32.Obfuscator.n (CLASSIC)
eGambitUnsafe.AI_Score_94%
FortinetW32/InnoMod.AYH
Cybereasonmalicious.657300
PandaTrj/CI.A

How to remove Malware.AI.4274392878?

Malware.AI.4274392878 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment