Malware

About “Malware.AI.4005417377” infection

Malware Removal

The Malware.AI.4005417377 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4005417377 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Malware.AI.4005417377?


File Info:

crc32: 6D805946
md5: f4d742fc056790ffc7f4443eac8bd432
name: F4D742FC056790FFC7F4443EAC8BD432.mlw
sha1: d5923d190f54cd4fc4e3799d74d5cca1dd0beda6
sha256: ddfc7d1f30680af16406e7f6d18f3d172df690b93198f0dc077df8375e16480a
sha512: b32df248fc9ef67b0a6eacc46c8c574725ae8858a103ec5599db19217a515fe395b512f905145791bd32975e2ff365edb5d7bcfba2980470ed2b2e2467a09458
ssdeep: 6144:jYxHBM406dnDqCVynsKpOTfgohmyFq4HE:jYxHt06ZDFVynskSfbFq4k
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 1981-1999
InternalName: CERTMGR.EXE
FileVersion: 5.131.2134.1
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows (R) 2000 Operating System
ProductVersion: 5.131.2134.1
FileDescription: ECM Certificate Manager
OriginalFilename: CERTMGR.EXE
Translation: 0x0409 0x04b0

Malware.AI.4005417377 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.om3@smCGl6ci
FireEyeGeneric.mg.f4d742fc056790ff
CAT-QuickHealTrojan.VBCrypt.MF.2790
Qihoo-360Win32/Trojan.6f2
ALYacGen:Trojan.Heur.om3@smCGl6ci
MalwarebytesMalware.AI.4005417377
VIPRELooksLike.Win32.Malware!vb (v)
SangforMalware
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderGen:Trojan.Heur.om3@smCGl6ci
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.c05679
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/VBInject.O!generic
APEXMalicious
AvastWin32:VB-AART [Trj]
ClamAVWin.Trojan.Vbkrypt-25599
NANO-AntivirusTrojan.Win32.VBKrypt.ekowul
TencentWin32.Trojan.Vbkrypt.Eeqx
Ad-AwareGen:Trojan.Heur.om3@smCGl6ci
EmsisoftGen:Trojan.Heur.om3@smCGl6ci (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureBackdoor.BDS/IRCBot.ZD
DrWebBackDoor.IRC.Bot.1413
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Mal/VBCheMan-C
IkarusTrojan.Win32.VBKrypt
JiangminTrojan.VBKrypt.ebla
AviraBDS/IRCBot.ZD
Antiy-AVLTrojan/Win32.VBKrypt
KingsoftWin32.Troj.VBKrypt.iu.(kcloud)
ArcabitTrojan.Heur.EAA489
GDataGen:Trojan.Heur.om3@smCGl6ci
CynetMalicious (score: 100)
Acronissuspicious
McAfeeVBObfus.ek
MAXmalware (ai score=83)
VBA32Trojan.Crypted.17115
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.NXE
RisingTrojan.VBKrypt!8.5C0 (CLOUD)
YandexTrojan.GenAsa!kV02Zcn/8Nk
SentinelOneStatic AI – Malicious PE – Spyware
eGambitUnsafe.AI_Score_86%
FortinetW32/Injector.NDP!tr
BitDefenderThetaAI:Packer.F7D07E4A1C
AVGWin32:VB-AART [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.4005417377?

Malware.AI.4005417377 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment