Malware

Malware.AI.840505854 removal tips

Malware Removal

The Malware.AI.840505854 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.840505854 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.840505854?


File Info:

name: C547B96C70808F8307E0.mlw
path: /opt/CAPEv2/storage/binaries/8f8689d1cb5ab76148b77dc026bfe627151b7878548da156b9f566255021e04d
crc32: DA74F834
md5: c547b96c70808f8307e081715d6c2176
sha1: 5e06f2c9d7fdb4a20ebe93c2b9b5bb7f25853cb8
sha256: 8f8689d1cb5ab76148b77dc026bfe627151b7878548da156b9f566255021e04d
sha512: e18abc52900f0cb33de9c45213b104cc822699c4cfb487545e7c09a8417ca19efffb8122837bbb4885e6d1891f083a5220558b1c9de01f915912a855eb9abc5e
ssdeep: 98304:o46Pd025/cDwCwpqJjZxzRlUorP2SJdf/DLqp1BWRhwArwXcj:/6ltwwqZ9Rl9CE1Du/Xcj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E43633230B8112F5E05B6EB62E46C911E716AD325C15499B3ACBDFBB5FBB36118083D3
sha3_384: a22c4d9dd1e81f6102fd150037e7bd9887d2db0e7104213a00d5279bc711e3136bd3fc3952ba73ffffc5577187ed0c15
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: File Backup Watcher 2.8.4.28 Setup
FileVersion: 2.8.4.28
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Malware.AI.840505854 also known as:

LionicTrojan.Win32.Ekstak.4!c
MalwarebytesMalware.AI.840505854
SangforTrojan.Win32.Agent.V7uh
CrowdStrikewin/malicious_confidence_100% (W)
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.antfi
AvastWin32:Trojan-gen
F-SecureTrojan.TR/AD.Nekark.nutqr
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.rc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.VXDH63
JiangminTrojan.Ekstak.chpv
AviraTR/AD.Nekark.nutqr
ZoneAlarmTrojan.Win32.Ekstak.antfi
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Malware-gen.R569293
McAfeeArtemis!C547B96C7080
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0DDS23
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.840505854?

Malware.AI.840505854 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment