Malware

Malware.AI.477372639 removal guide

Malware Removal

The Malware.AI.477372639 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.477372639 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.477372639?


File Info:

name: 8A4402FB62DAD7D80BA4.mlw
path: /opt/CAPEv2/storage/binaries/52bcedc4249909d329b93edcc81e4d9d6ba19406827dccc1824cfabfffeb919b
crc32: 72E4000A
md5: 8a4402fb62dad7d80ba41e6a046c6ccd
sha1: 40307c4c021f48834223cda520713caf3a7e8287
sha256: 52bcedc4249909d329b93edcc81e4d9d6ba19406827dccc1824cfabfffeb919b
sha512: a8e178e67c45d05e4df7c0f8f177dec7b634059b7c62829e1ad782006ca2b61c3a72344a04738bc717435e4a1be575d4b9b568c8af8f37d823f9ce544a0a23f1
ssdeep: 3072:Un10AV+j62uiqR/omVq+0996E/GBDph63+m9W6HMRmVrynarATrgpBtJHSWfAmjn:UncuXiqRAmV3bE/G15mA6wnasTrotpRD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1260402D357898A2CF455A239408BAF6CAB7CDCD318D6079260857E392D3D948FE1F227
sha3_384: b3878b69b43e0738b12ae8856f8d98c93a2b36ed726b5d5aee597bf7122631c8fccfc27d259d86ab4e162326b1c3dfc7
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: uusee
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Malware.AI.477372639 also known as:

LionicTrojan.Win32.Strictor.4!c
DrWebTrojan.Siggen3.25765
MicroWorld-eScanGen:Variant.Strictor.1860
FireEyeGen:Variant.Strictor.1860
ALYacGen:Variant.Strictor.1860
CylanceUnsafe
VIPREGen:Variant.Strictor.1860
SangforTrojan.Win32.Chinflej.V8h0
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/Chinflej.e90cb7f0
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.b62dad
BitDefenderThetaGen:NN.ZelphiF.34806.lO0ba0PGmCkb
VirITTrojan.Win32.Generic.ACBT
CyrenW32/Delf.AV.gen!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Chinflej.AK
TrendMicro-HouseCallTROJ_AGENT_027583.TOMB
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-613878
BitDefenderGen:Variant.Strictor.1860
NANO-AntivirusTrojan.Win32.Agent.dgfhr
AvastWin32:Trojan-gen
RisingTrojan.Win32.Fedwj.i (CLOUD)
Ad-AwareGen:Variant.Strictor.1860
SophosMal/Generic-S
ZillyaTrojan.Agent2.Win32.15613
TrendMicroTROJ_AGENT_027583.TOMB
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.1860 (B)
IkarusTrojan.Win32.Agent
GDataGen:Variant.Strictor.1860
JiangminTrojan/Agent.fzkp
AviraTR/ATRAPS.Gen7
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.11D
ArcabitTrojan.Strictor.D744
ViRobotTrojan.Win32.A.Agent.186880.D[ASPack]
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Agent.R16473
McAfeeArtemis!8A4402FB62DA
VBA32Trojan.Agent2
MalwarebytesMalware.AI.477372639
APEXMalicious
TencentMalware.Win32.Gencirc.10b62adb
YandexTrojan.GenAsa!8WBoZ10Bdms
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Chinflej.AK!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.477372639?

Malware.AI.477372639 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment