Malware

Should I remove “Malware.AI.462059468”?

Malware Removal

The Malware.AI.462059468 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.462059468 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the IcedIDStage1 malware family

How to determine Malware.AI.462059468?


File Info:

name: 408DBE14138F774AE0EB.mlw
path: /opt/CAPEv2/storage/binaries/45c2638df5a79badd2fd7cfb786d6e8ace4adbbb580bc30100016fad3fc95aeb
crc32: BCFE4F5A
md5: 408dbe14138f774ae0eb6f25766945a0
sha1: 3198e9463171b3d4e835be2659c6bbcfdf91738f
sha256: 45c2638df5a79badd2fd7cfb786d6e8ace4adbbb580bc30100016fad3fc95aeb
sha512: 59f40a23fd64df344c68c846dfb4286353a07711f7cd48a2e3c639e1efe2dd86c93463c7bf5ff2c68bace1fe190fe8fce093c29576db8b0a29cdd7c7d0ed6bfc
ssdeep: 6144:MuefYKuq5zuR4hcQqz3qxdikUJP5fj1PYNjRIjYqNft:MLfYKuq8+EWtUR5JOOj/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C44F11277E0D471D08121352CE2D7A1AB6EFC519F75C617BAECB63B2E742C08A27396
sha3_384: a9521805d46c4af9e9639734db8f68feae179d416450bab83a309ddd4b071955a803c8269b78f0458f494f0600b0ec98
ep_bytes: e878190000e989feffff8bff558bec83
timestamp: 2011-11-05 12:38:04

Version Info:

CompanyName: Sonic Boom Wellness Effect
FileDescription: Shellhow
FileVersion: 15.7.91.58
InternalName: Shellhow
LegalCopyright: Copyright © 2005- 2015 Sonic Boom Wellness Effect
LegalTrademarks: Shellhow
ProductVersion: 15.7.91.58
OriginalFilename: simplehere.exe
ProductName: Shellhow
Translation: 0x0409 0x04b0

Malware.AI.462059468 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Agent.DIKF
FireEyeGeneric.mg.408dbe14138f774a
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Agent.DIKF
CylanceUnsafe
ZillyaTrojan.Generic.Win32.385461
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056e9401 )
BitDefenderTrojan.Agent.DIKF
K7GWTrojan ( 0056e9401 )
Cybereasonmalicious.4138f7
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GMNT
CynetMalicious (score: 99)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generickdz-7371458-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDropper:Win32/dropper.ali1003001
NANO-AntivirusTrojan.Win32.IcedID.fjyfec
RisingTrojan.GenKryptik!8.AA55 (TFE:5:eGsFGjuobhF)
Ad-AwareTrojan.Agent.DIKF
SophosMal/Generic-S
ComodoTrojWare.Win32.IcedID.NT@7ytcyj
DrWebTrojan.IcedID.15
VIPRETrojan.Agent.DIKF
TrendMicroTrojanSpy.Win32.URSNIF.SMKA0.hp
McAfee-GW-EditionGenericRXGO-OQ!408DBE14138F
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.DIKF (B)
JiangminTrojan.Generic.cuvzj
AviraHEUR/AGEN.1229087
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.4F62
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Agent.DIKF
SUPERAntiSpywareTrojan.Agent/Gen-Banker
GDataTrojan.Agent.DIKF
GoogleDetected
AhnLab-V3Malware/Gen.Generic.C2817434
Acronissuspicious
McAfeeGenericRXGO-OQ!408DBE14138F
VBA32TrojanBanker.IcedID
MalwarebytesMalware.AI.462059468
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMKA0.hp
TencentMalware.Win32.Gencirc.10b2d672
YandexTrojan.PWS.IcedID!zeB8+HaFHfE
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.GMLM!tr
BitDefenderThetaGen:NN.ZexaF.34726.pq0@aS!hfCli
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove Malware.AI.462059468?

Malware.AI.462059468 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment