Malware

About “Malware.AI.1936536040” infection

Malware Removal

The Malware.AI.1936536040 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1936536040 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.1936536040?


File Info:

name: 448BB9F14F114249991B.mlw
path: /opt/CAPEv2/storage/binaries/8eedf4d738ba3b1d3ad0a21e2ff87fef326d56f4e7669e5adc89a86a4b74c085
crc32: 4D67B5CB
md5: 448bb9f14f114249991bd587e6483cd4
sha1: c74b27d6178a23af376cfdad4336eea8b0f8bc12
sha256: 8eedf4d738ba3b1d3ad0a21e2ff87fef326d56f4e7669e5adc89a86a4b74c085
sha512: 30e41fd78bd9dcf8678d3cdd8bf9de7a480388e428489c6fe874c9235f1152a0b0fd7a3ea1cec23ebceae9d107a2b124a6ebabb5cc01e70322e922c98293739b
ssdeep: 768:+EhSeqZwJg1e1GiCyd92Do3H8Pw/+3Kk8Brvq:+klqZEg15i1qf52rvq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D6637C43F6E0D572C150C9FD9D07BA18AA7F36302D545492AEF61FCFA91E2405D2C2AB
sha3_384: 58f2c01768de073e7cfa064a1086cb8b9a3333662cac742f937ee5cb118c2dd15d5f94ccbfd97d68326eb630c3315d6b
ep_bytes: 4dfcba68644000a1b4984000e867e9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.1936536040 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Eggnog.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.278372
ClamAVWin.Worm.Fearso-7358009-0
McAfeeGenericRXVY-LU!448BB9F14F11
MalwarebytesMalware.AI.1936536040
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a42631 )
AlibabaTrojan:Win32/Eggnog.6c55b28e
K7GWTrojan ( 005a42631 )
Cybereasonmalicious.6178a2
BitDefenderThetaGen:NN.ZexaF.36250.eGZ@aKhJMJg
VirITWorm.Win32.Eggnog.B
CyrenW32/Eggnog.K.gen!Eldorado
SymantecW32.Nofer.A@mm
ESET-NOD32a variant of Win32/Agent_AGen.AWA
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fugrafa.278372
AvastWin32:WormX-gen [Wrm]
TencentWin32.Trojan.Redcap.Xdkl
TACHYONTrojan/W32.Fugrafa.69632
EmsisoftGen:Variant.Fugrafa.278372 (B)
BaiduWin32.Worm.Eggnog.a
F-SecureTrojan.TR/Redcap.niatb
VIPREGen:Variant.Fugrafa.278372
TrendMicroTROJ_GEN.R03BC0CED23
McAfee-GW-EditionBehavesLike.Win32.Generic.kz
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.448bb9f14f114249
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fugrafa.278372
AviraTR/Redcap.niatb
Antiy-AVLTrojan/Win32.Eggnog
ArcabitTrojan.Fugrafa.D43F64
MicrosoftTrojan:Win32/Eggnog.MA!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Eggnog.R567010
ALYacGen:Variant.Fugrafa.278372
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0CED23
RisingTrojan.Eggnog!8.E7F0 (TFE:4:y1RWr2LaOiM)
YandexTrojan.Agent_AGen!Pk1vuy82kDg
IkarusEmail-Worm.Win32.Fearso
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.AGEN!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.1936536040?

Malware.AI.1936536040 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment