Malware

Malware.AI.4277887196 (file analysis)

Malware Removal

The Malware.AI.4277887196 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4277887196 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Malware.AI.4277887196?


File Info:

name: 29AA969F442361243F3F.mlw
path: /opt/CAPEv2/storage/binaries/67a1fc8e05c8e7efa54649d8a033b5e8c74e0dde8c83303413cbf4b453f58533
crc32: A97B7E4C
md5: 29aa969f442361243f3f52a2e0f1e0a0
sha1: d6889b11e125ae0aa95e6388e0383648d5049ff1
sha256: 67a1fc8e05c8e7efa54649d8a033b5e8c74e0dde8c83303413cbf4b453f58533
sha512: 669f42631afd83a5da25605c9d6c9ab5b913a3468eda2fb96aadcb0ba25c39cb9b543386c86b9940a2788a8cf061ce1c8eaeddfd0718fb9ff829be746ad1c344
ssdeep: 6144:PD/ucXKg1AYJTKRT0/q0/DpnAMSv8gS+BA+mhHkhdPcExjbTYqJWNB6kMXkikZ:PDm1guY+TU/9nABF1h7kExjblc82
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EC42387B8080E98DAF673B180D828CD9374EBA4FBF37E170BDD6209557A78479A1314
sha3_384: bfc0e689cabcda4d286b63bc44c08585efd382a6d135865d4f19205006b535064ba8450797e40b67a62df15965bc04de
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2010-05-06 06:23:11

Version Info:

CompanyName: 湖北盛天网络技术有限公司
FileDescription:
FileVersion: 6.0.2.430
InternalName: E-yoo Service
LegalCopyright: Copyright (C) 2010 Century NetWork Technology CO., Ltd.
LegalTrademarks:
OriginalFilename:
ProductName: E-yoo Client Start Service
ProductVersion: 6.0.2.430
Comments:
Translation: 0x0804 0x03a8

Malware.AI.4277887196 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.69883248
FireEyeGeneric.mg.29aa969f44236124
SkyhighBehavesLike.Win32.Rootkit.hc
ALYacTrojan.GenericKD.69883248
MalwarebytesMalware.AI.4277887196
SangforTrojan.Win32.Agent.V1zm
Cybereasonmalicious.1e125a
ArcabitTrojan.Generic.D42A5570
BitDefenderThetaGen:NN.ZelphiF.36792.I00bamPo3Cpj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-988450
BitDefenderTrojan.GenericKD.69883248
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.69883248 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan.GenericKD.69883248
Trapminemalicious.high.ml.score
SophosMal/EncPk-AQN
IkarusTrojan-Banker.Win32.Banker
VaristW32/Trojan.RYLK-2639
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare/Win32.Generic
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.69883248
GoogleDetected
McAfeeArtemis!29AA969F4423
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09JN23
RisingMalware.Undefined!8.C (TFE:5:qtrSVC9xTOV)
SentinelOneStatic AI – Suspicious PE
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.4277887196?

Malware.AI.4277887196 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment