Malware

Malware.AI.4016639641 removal guide

Malware Removal

The Malware.AI.4016639641 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4016639641 virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Sniffs keystrokes
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Created a service that was not started
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.wk1888.com
www.lang32.com
www.af0575.com
www.fz0575.com
106.jz666.work
users.qzone.qq.com
crl4.digicert.com
ocsp.dcocsp.cn
crl.digicert-cn.com
crl3.digicert.com

How to determine Malware.AI.4016639641?


File Info:

crc32: 087AF25E
md5: e57416e1935a33a9f173da150d8daa05
name: E57416E1935A33A9F173DA150D8DAA05.mlw
sha1: 3e3df3ab52a25d8a451201d2b4c8422848fdc138
sha256: 4176f2c029ae72c4bf087aa6fe76adff915ad75a41c1b9a8d28b71835052c87a
sha512: 201b3ef182246c62b70ec9740f54949c4d8cd1de8789de3cf58944aa124ad93708dace137ae28dfa3a82fb863e9a8e741c2014aa49cb6ef1002692067405b1b2
ssdeep: 6144:/QqaV8iAxOQmDIqpV5LBZJveaCzlH8KQALPsL2lJbZJ:QVyxOpdpVZJ/CzPQAA2ltZJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Malware.AI.4016639641 also known as:

K7AntiVirusTrojan-Downloader ( 0055e3da1 )
DrWebTrojan.DownLoader19.23899
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Magania.18692
ALYacMemScan:Trojan.GenericKDZ.41799
SangforTrojan.Win32.Save.a
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.1935a3
BaiduMulti.Threats.InArchive
CyrenW32/Trojan.IM.gen!Eldorado
SymantecBackdoor.Trojan
ESET-NOD32multiple detections
ZonerTrojan.Win32.83819
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Farfli-9811912-0
KasperskyTrojan-Downloader.Win32.Dupzom.blr
BitDefenderMemScan:Trojan.GenericKDZ.41799
NANO-AntivirusTrojan.Win32.Dwn.eahibw
MicroWorld-eScanMemScan:Trojan.GenericKDZ.41799
TencentWin32.Trojan-downloader.Dupzom.Ajuy
Ad-AwareMemScan:Trojan.GenericKDZ.41799
SophosTroj/AutoG-JE
ComodoTrojWare.Win32.Agent.PDSB@4q3i1w
BitDefenderThetaGen:NN.ZexaF.34690.cq0@aqF6coeb
TrendMicroBKDR_ZEGOST.SM50
McAfee-GW-EditionBackDoor-EMA.gen.e
FireEyeMemScan:Trojan.GenericKDZ.41799
EmsisoftMemScan:Trojan.GenericKDZ.41799 (B)
JiangminTrojan/Dialer.mgr
AviraHEUR/AGEN.1124319
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Dorv.A
ArcabitTrojan.Generic.DA347
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataWin32.Trojan-Downloader.Agent.WC
AhnLab-V3Trojan/Win.Generic.R419237
McAfeeGenericRXGZ-NM!4B19377ADE95
MAXmalware (ai score=80)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.4016639641
TrendMicro-HouseCallBKDR_ZEGOST.SM50
RisingBackdoor.Farfli!8.B4 (RDMK:cmRtazojdhNbzDwVnpD4AxNBfQpf)
YandexTrojan.GenAsa!puNbw774luA
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Agent.BVS!tr
AVGWin32:Malware-gen

How to remove Malware.AI.4016639641?

Malware.AI.4016639641 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment