Malware

About “Malware.AI.4003486881” infection

Malware Removal

The Malware.AI.4003486881 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4003486881 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools

How to determine Malware.AI.4003486881?


File Info:

name: 2FF061116554A5749EEC.mlw
path: /opt/CAPEv2/storage/binaries/9f60920853199f607f841679e9ea1fd092eab4e16ec01bfdc34e84ff708b65dc
crc32: C73A0192
md5: 2ff061116554a5749eeca6b44f43c319
sha1: 0fc9e4f8a68846342a66afbdc08e7176f3b02f80
sha256: 9f60920853199f607f841679e9ea1fd092eab4e16ec01bfdc34e84ff708b65dc
sha512: 86e24e7afff4a1b9c88e155fee7b776f739e388eff6ae0db20d0f4ae243a94067f8338ae35fc84c205aa3f593545308bae34cb78b86682d3cbe59fade57ddcdd
ssdeep: 384:t6BDA/aD2mFRiJNhWoHz8zUc4zHovYjtp:t6J2KiJLWoHzEUc6c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T120529E72D61BE4F1C584A8B2346B563323378444C3D5A7662DC9297FE8EA71C1D9C0A8
sha3_384: e197f0f0d4486337f957e5caf072291e6675cd8727cec498459afd6caf9257b71887c0d271722cb427720b464bd6182f
ep_bytes: 60be007040008dbe00a0ffff5783cdff
timestamp: 2004-05-18 08:33:10

Version Info:

0: [No Data]

Malware.AI.4003486881 also known as:

BkavW32.AIDetect.malware2
CylanceUnsafe
VIPRETrojan.Win32.Agent.abzlz
SangforInfostealer.Win32.Zbot.ml
Cybereasonmalicious.8a6884
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.RG potentially unsafe
APEXMalicious
ClamAVWin.Trojan.Agent-890350
SophosGeneric PUA AP (PUA)
ComodoMalware@#2ypptotx5db5h
McAfee-GW-EditionBehavesLike.Win32.PWSOnlineGames.lh
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Bumat!rts
McAfeeRDN/Generic PUP.bld
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.4003486881
RisingTrojan.Bumat!8.710 (CLOUD)
YandexTrojan.Bumat!vtXchOPhyik
FortinetW32/Malware_fam.NB

How to remove Malware.AI.4003486881?

Malware.AI.4003486881 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment