Malware

Should I remove “Malware.AI.5147756”?

Malware Removal

The Malware.AI.5147756 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.5147756 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

wpad.local-net
www.56561234.com

How to determine Malware.AI.5147756?


File Info:

name: 17FE4E3C68B5FD09002F.mlw
path: /opt/CAPEv2/storage/binaries/f4b7b3c6d9aa60a5a09301067c11fd591c5b8b22e2405bde1e21a016dd7d3dd6
crc32: 00557F53
md5: 17fe4e3c68b5fd09002f3c8884b7ac53
sha1: 833eac98070cfc374b76598164dba989f96cc7a2
sha256: f4b7b3c6d9aa60a5a09301067c11fd591c5b8b22e2405bde1e21a016dd7d3dd6
sha512: e42cf1691a5089ab8581da59316961c5c8e9ff6c2a583b64e24f2ce223562663d2154709985df9d5af4cdce8dfcf7682c0f7d9ca9ad1543c7c30f2689154c9e6
ssdeep: 384:MSWIKU3tkDAYhW2gHxw5a6YXduS00e97JIY77ovUshKSJuOw7:MSVKU3tkDa2CxaJSs97JIHD3JuOi
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1F2B26E0B9E5640B2D61A84B2C6778611EFFE781236D63C4FAB50F5C61F71280D1FB46A
sha3_384: 6d036b4de10023786a76fc95b35b4ce42cadee481ce7eb55c7cc4cc004d25b3198086f14283a1f6ec547013ea41a22a7
ep_bytes: 4883ec28e8db0300004883c428e9fefc
timestamp: 2021-07-18 23:09:17

Version Info:

0: [No Data]

Malware.AI.5147756 also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.36378
MicroWorld-eScanTrojan.Generic.30278312
FireEyeGeneric.mg.17fe4e3c68b5fd09
CAT-QuickHealTrojan.Agent
ALYacTrojan.Generic.30278312
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0057ddd01 )
AlibabaTrojanDownloader:Win64/MalwareX.f7a77934
K7GWTrojan-Downloader ( 0057ddd01 )
Cybereasonmalicious.8070cf
BitDefenderThetaGen:NN.ZexaE.34294.aqX@a8U7DRii
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/TrojanDownloader.Agent.KI
TrendMicro-HouseCallTROJ_GEN.R002C0WKM21
Paloaltogeneric.ml
ClamAVWin.Malware.Latot-9879382-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.Generic.30278312
NANO-AntivirusTrojan.Win32.Small.ixtpml
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.Generic.30278312
EmsisoftTrojan.Generic.30278312 (B)
F-SecureHeuristic.HEUR/AGEN.1143315
TrendMicroTROJ_GEN.R002C0WKM21
McAfee-GW-EditionBehavesLike.Win64.Dropper.mm
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.30278312
JiangminTrojan.Schoolboy.kl
AviraHEUR/AGEN.1143315
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.SchoolBoy
GridinsoftRansom.Win64.Wacatac.sa
ArcabitTrojan.Generic.D1CE02A8
ViRobotTrojan.Win32.Z.Agent.25276.A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R434899
McAfeeArtemis!17FE4E3C68B5
VBA32Trojan.Schoolboy
MalwarebytesMalware.AI.5147756
TencentMalware.Win32.Gencirc.11d90ca6
YandexTrojan.SchoolBoy!HUtwSUUD4Hs
IkarusTrojan-Downloader.Win32.Small
FortinetW64/Agent.KI!tr.dldr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.5147756?

Malware.AI.5147756 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment