Malware

About “Malware.AI.4012704637” infection

Malware Removal

The Malware.AI.4012704637 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4012704637 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4012704637?


File Info:

name: 63529952A3C173E29D15.mlw
path: /opt/CAPEv2/storage/binaries/b1bd685052834d3f6d954053d2a672beaae6d71e85a15c91eaaacdef0fe2b1e3
crc32: 4DDFD03C
md5: 63529952a3c173e29d1514e371f7d1c5
sha1: 6cda602fd2dc3681f571198062243adaedeb0ec7
sha256: b1bd685052834d3f6d954053d2a672beaae6d71e85a15c91eaaacdef0fe2b1e3
sha512: cef175232a8735fd2b2d0bd7de54cef78efad6337781437ae9ee778aba7cf6c1a6ec20fd2cbf1b24249182171285de64feed21dfa808f03d3426e6485c0a9bc9
ssdeep: 196608:91OogS8ynmIBQMbUSGhoeuKWotc1/cul6YBZvsrfGLDMAgvc:3O48wmI6iRGhov9B1j6iszUDmc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1127633243295C8B2DACB24331DA83BD0A8FAC7566D30986377CEAD497DB4499417ACF4
sha3_384: e90c1c0fd45e655918a6b2a61a7ad8121e14131d4204649d2ec075e187ec42f818d9f3de673fbf5d08023b1a0b10f24e
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

Malware.AI.4012704637 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.39881
FireEyeGen:Variant.Jaik.39881
McAfeeArtemis!63529952A3C1
CylanceUnsafe
Cybereasonmalicious.2a3c17
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Jaik.39881
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Jaik.39881
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
EmsisoftGen:Variant.Jaik.39881 (B)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataGen:Variant.Jaik.39881
ALYacGen:Variant.Jaik.39881
MAXmalware (ai score=81)
MalwarebytesMalware.AI.4012704637
TrendMicro-HouseCallTROJ_GEN.R002H09L821
FortinetW32/PossibleThreat
AVGWin32:Malware-gen

How to remove Malware.AI.4012704637?

Malware.AI.4012704637 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment