Malware

Malware.AI.445565364 malicious file

Malware Removal

The Malware.AI.445565364 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.445565364 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.445565364?


File Info:

name: FC7E84F0F449262E3956.mlw
path: /opt/CAPEv2/storage/binaries/4c701e195b6e3e17a9c6bb46bc7c3f65352b4844d7b7aa78b55c5271a704a449
crc32: 7ED3C930
md5: fc7e84f0f449262e3956fb1779c98110
sha1: ff071a8c3444ece30533dcfd154b9a4f5e241ad0
sha256: 4c701e195b6e3e17a9c6bb46bc7c3f65352b4844d7b7aa78b55c5271a704a449
sha512: a57c34b2bb9178bc94f085257ab18f2df8ccf0b595a6cc7abf6b780940fb2ec9906c869e1a51234ebd1c9110f992e638ba3ae85f485865c6e2c35c944a88f98b
ssdeep: 3072:lYsdy6hsnQDGbaZgSCC6mj4OjaCsoG49a43bh8xN7eNz97pTkUjPyZG:iss6hsQDIax10f49V8b4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10AF37B81D3E94289F5F71B30D8BB62994D7ABF55A829C64E0A540D4D0A31E0C8E7BF37
sha3_384: 6419dc3804b1ff4c52f2e5e3b5627ebadf9def78ba11c9889f51b7a94f497ef852964f57ff4c6ebedf200c340f0fcc2f
ep_bytes: 558bec6aff686083400068c07d400064
timestamp: 2021-11-24 15:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z SFX small
FileVersion: 21.06
InternalName: 7zS2.sfx
LegalCopyright: Igor Pavlov : Public domain
OriginalFilename: 7zS2.sfx.exe
ProductName: 7-Zip
ProductVersion: 21.06
Translation: 0x0409 0x04b0

Malware.AI.445565364 also known as:

LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanTrojan.GenericKD.38902923
FireEyeTrojan.GenericKD.38902923
McAfeeArtemis!FC7E84F0F449
MalwarebytesMalware.AI.445565364
SangforTrojan.Win32.Agent.gen
K7AntiVirusTrojan ( 0058e0221 )
AlibabaTrojan:Win32/Generic.2822a9d9
K7GWTrojan ( 0058e0221 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FQBH
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.38902923
TencentWin32.Trojan.Agent.Efkw
EmsisoftTrojan.GenericKD.38902923 (B)
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
JiangminTrojan.Agent.dtps
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.Z.Agent.158477.A
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataWin32.Trojan.Agent.H3TXCR
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38902923
APEXMalicious
RisingTrojan.Agent!8.B1E (CLOUD)
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.FQBH!tr

How to remove Malware.AI.445565364?

Malware.AI.445565364 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment