Malware

Malware.AI.4006551309 information

Malware Removal

The Malware.AI.4006551309 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4006551309 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4006551309?


File Info:

name: 840F02FBFF128346B4C2.mlw
path: /opt/CAPEv2/storage/binaries/306286f7656b04adb05903d808131a8098298a09f3ca79a677392c18f8c61a1d
crc32: 4DBC2730
md5: 840f02fbff128346b4c27db8bcee9125
sha1: 2439b7e60bef847adc33a066876ee6d8cc5122ed
sha256: 306286f7656b04adb05903d808131a8098298a09f3ca79a677392c18f8c61a1d
sha512: ddc0056d3a51768eca7e5da8cddceaa1487ce3d335f3d1355dec05400efa97a2b8c62fcfdc0d72ac9074ecc7bdfd404d3001d9875b3fb8a1f67b08f2300cf73f
ssdeep: 49152:JQK1hGKAQdku/seZZPUdw5JvWYDMhzj1eHKibciRqenfDyGQgS:JQKL2i/siPUC5Jv0A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BC5BF26BB4E9072D1721071771DE76714A875312B6650CBF3C1AF2E29E0AD3BA39E07
sha3_384: 75f47d248f284d1a7d85f7c960464df485bda2ce42c1c35cd80fe2ded71db9936edcd02edf19fe88b8f69e7586e5405e
ep_bytes: e8c2040000e980feffff558bec5156ff
timestamp: 2018-08-10 07:12:22

Version Info:

0: [No Data]

Malware.AI.4006551309 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
CAT-QuickHealTrojan.Skeeyah.S3293683
MalwarebytesMalware.AI.4006551309
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 00535f0d1 )
K7GWAdware ( 00535f0d1 )
Cybereasonmalicious.60bef8
CyrenW32/S-2a1c663c!Eldorado
SymantecPUA.Downloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
ClamAVWin.Malware.Softcnapp-6787524-0
KasperskyHEUR:Trojan.Win32.Generic
AvastWin32:MalwareX-gen [Trj]
TencentTrojan.Win32.Generic.e
EmsisoftApplication.Generic (A)
F-SecureHeuristic.HEUR/AGEN.1319114
DrWebAdware.Softcnapp.92
ZillyaTrojan.Generic.Win32.1707555
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.840f02fbff128346
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Adload.wgj
GoogleDetected
AviraHEUR/AGEN.1319114
Antiy-AVLTrojan/Win32.AGeneric
XcitiumApplication.Win32.AdWare.Softcnapp.O@80ok4p
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Helper.R233980
McAfeeSoftcnapp
VBA32BScope.Adware.Puwaders
Cylanceunsafe
PandaTrj/Genetic.gen
RisingAdware.Downloader!1.BBEC (CLASSIC)
YandexTrojan.GenAsa!01c2HtNIKYM
IkarusPUA.Softcnapp
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/Softcnapp
BitDefenderThetaGen:NN.ZexaF.36196.KAW@auQMG8pj
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.4006551309?

Malware.AI.4006551309 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment