Malware

Malware.AI.4274575771 information

Malware Removal

The Malware.AI.4274575771 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4274575771 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4274575771?


File Info:

name: F3520106A104E65CCB22.mlw
path: /opt/CAPEv2/storage/binaries/6febfbc3af5b4271c979cee2ae89bdfa5358e300e580dcfc46e6f2e3e9f3ee2a
crc32: 2DBE599A
md5: f3520106a104e65ccb2258234907d134
sha1: c748ae35afb4837ae9eb5ea01866649f41e279df
sha256: 6febfbc3af5b4271c979cee2ae89bdfa5358e300e580dcfc46e6f2e3e9f3ee2a
sha512: 8fcbf66d29f84d1cb8720a42c77b9e4c0b4dcadcc945819069cd16687d795407262427b71ea74d66e8161b55ed3d873430100560fff64eee8dfd73d51d99c15e
ssdeep: 49152:Cg0jdcUSxMy2RQj9FUydmMmID1mYmv27yQ3ZpShZnCqUNxsKr/5PtKfHAvAf:abSxMywqDUyB1mYmvsdZpSZCqgr/5Pts
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124E5330377C30971F4F9493C85B101A09E2F75390DFAA22A2EBCDB0E5A399D64477B66
sha3_384: 7216d6db958dd924c431fb350a24c8d28c426f3670c8a8327e4768737e547c7c413f1d22f30dca03279bb81ca51a6f3b
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2015-07-16 13:24:20

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: A Software Plus
FileDescription: Cool MPEG To 3GP Converter Setup
FileVersion: 1.0
LegalCopyright: Copyright © 2008-2009 A Software Plus
ProductName: Cool MPEG To 3GP Converter
ProductVersion: 1.0
Translation: 0x0000 0x04b0

Malware.AI.4274575771 also known as:

DrWebAdware.Relevant.189
McAfeeArtemis!F3520106A104
CylanceUnsafe
K7AntiVirusAdware ( 00524b301 )
K7GWAdware ( 00524b301 )
SymantecPUA.Gen.2
ESET-NOD32multiple detections
Kasperskynot-a-virus:AdWare.Win32.Relevant.nks
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SophosGeneric PUA MH (PUA)
GDataWin32.Application.RelevantKnowledge.G
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftPUA:Win32/Bitrepeyp.A
VBA32Adware.Relevant
MalwarebytesMalware.AI.4274575771
SentinelOneStatic AI – Suspicious PE

How to remove Malware.AI.4274575771?

Malware.AI.4274575771 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment