Malware

Malware.AI.4006045902 removal guide

Malware Removal

The Malware.AI.4006045902 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4006045902 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

www.racevx.xyz
www.twohomesforone.com
www.mazdavalencia.com
www.dsonomashops.com
www.maxhuski.com
www.blessingbyte.com
www.shawahe.info
www.brokod.com
www.111765a.com
www.healthyshipment.com

How to determine Malware.AI.4006045902?


File Info:

crc32: 3AF533EA
md5: b13ea41d6b13b894637e9def24df864d
name: B13EA41D6B13B894637E9DEF24DF864D.mlw
sha1: 3a8f79145e492cc417a400c3344a656153fd5245
sha256: f74318d49a5910f77a11bf60335a1a00fabf658fa498a8c03ed7d28d5749ed5a
sha512: f08b19ef08b3facfba9a87e6a7f708a88b90dd39c6d9d3343ea18a115dcf2188de2da71d89c49c17e752263537cf7c72cccf3a611a80a2e56dd02ddcd7e06513
ssdeep: 24576:cKz0Xl/w7Y8udCElk9bKzK+56ONIm5pbE736:ulo7Ynu5KzK+YiJ5pr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4006045902 also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.b13ea41d6b13b894
McAfeeArtemis!B13EA41D6B13
SangforMalware
BitDefenderAIT:Trojan.Nymeria.4398
Cybereasonmalicious.45e492
CyrenW32/Trojan.XTQK-1075
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Injuke.gen
MicroWorld-eScanAIT:Trojan.Nymeria.4398
Ad-AwareAIT:Trojan.Nymeria.4398
SophosMal/Generic-S + Troj/Formbo-RZ
ComodoMalware@#wr3b6nm4p8n9
DrWebTrojan.DownLoader36.37989
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.th
EmsisoftAIT:Trojan.Nymeria.4398 (B)
IkarusTrojan.Autoit
MAXmalware (ai score=81)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AAF7
GridinsoftTrojan.Win32.Downloader.oa!s1
ArcabitAIT:Trojan.Nymeria.D112E
ZoneAlarmHEUR:Trojan.Win32.Injuke.gen
GDataWin32.Trojan-Stealer.FormBook.VKKNFX
VBA32suspected of VBS.EncodedMalware
MalwarebytesMalware.AI.4006045902
APEXMalicious
ESET-NOD32Win32/Formbook.AA
SentinelOneStatic AI – Suspicious PE
FortinetAutoIt/Agent.5A2D!tr
WebrootTrojan.Dropper.Gen
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Injuke.HyoD57cA

How to remove Malware.AI.4006045902?

Malware.AI.4006045902 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment