Malware

Malware.AI.4009439832 malicious file

Malware Removal

The Malware.AI.4009439832 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4009439832 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4009439832?


File Info:

name: B7B9D42416128BD08460.mlw
path: /opt/CAPEv2/storage/binaries/68d989d6318fa367701c05fbf7799e6374e939298900d5d35fe6cd5a39b1ee49
crc32: E57315B6
md5: b7b9d42416128bd084604dd64fb9189a
sha1: 0a48cc8eace509cfe7fb5243a7db8f43999a4c8c
sha256: 68d989d6318fa367701c05fbf7799e6374e939298900d5d35fe6cd5a39b1ee49
sha512: d5999368ef5f8e19ebf80c9a3dc033f9306fc40eb6d80a47e0682b936302ca418f3bba5ad55e2043e7a9caaf05bf9c9e59abe19bd424533f846fbcba3a04873a
ssdeep: 12288:kjim++us0QaaI0lcMGc5yn88Fcve0oE7IOLt5:4++us0XaQuEWeqDLt5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4A4F16FDC87CD86C272C9BE8086BA129FB6EE04A2C45645D144F5EFE275391EB18703
sha3_384: f39c90ae3d1d909091b9b9a9dcb77ca146e890bc9e48222a9b6ed361ab82e5a252b947053ea437fd03d8587d0fa492a4
ep_bytes: 60be00e04f008dbe0030f0ff57eb0b90
timestamp: 2022-02-23 06:08:37

Version Info:

FileVersion: 1.0.0.0
FileDescription: huisihudong studio
ProductName: 无名电商下图
ProductVersion: 1.0.0.0
CompanyName: huisihudong studio
LegalCopyright: huisihudong studio
Comments: huisihudong studio
Translation: 0x0804 0x04b0

Malware.AI.4009439832 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lpZC
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.32419773
FireEyeGeneric.mg.b7b9d42416128bd0
ALYacTrojan.Generic.32419773
MalwarebytesMalware.AI.4009439832
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Disabler.9955ac6c
K7GWTrojan ( 005246d51 )
CrowdStrikewin/grayware_confidence_60% (D)
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Generic.32419773
NANO-AntivirusTrojan.Win32.Mlw.jqsitn
AvastWin32:Malware-gen
EmsisoftTrojan.Generic.32419773 (B)
VIPRETrojan.Generic.32419773
TrendMicroTROJ_GEN.R002C0PE723
McAfee-GW-EditionBehavesLike.Win32.Backdoor.gc
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.161DS2T
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Generic.D1EEAFBD
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5022552
McAfeeRDN/Generic.dx
MAXmalware (ai score=84)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PE723
RisingTrojan.Generic@AI.100 (RDML:giVy+4JRxB/H3Mg8AdrC9Q)
IkarusTrojan.Win32
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.1E2FC7!tr
BitDefenderThetaGen:NN.ZexaF.36250.DmKfa0pQGYpb
AVGWin32:Malware-gen
Cybereasonmalicious.eace50
DeepInstinctMALICIOUS

How to remove Malware.AI.4009439832?

Malware.AI.4009439832 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment