Malware

Malware.AI.4017168208 information

Malware Removal

The Malware.AI.4017168208 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4017168208 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4017168208?


File Info:

name: 606AC0D7CC06CBB26B25.mlw
path: /opt/CAPEv2/storage/binaries/4a1a728829af0905ed2a6916f99e151f6073c9d0a3e4cd99af9623a88ee3593d
crc32: D00472F3
md5: 606ac0d7cc06cbb26b25da0f7ba39690
sha1: 96c72e40b8a111bada52b89813e3104b21b8b8a7
sha256: 4a1a728829af0905ed2a6916f99e151f6073c9d0a3e4cd99af9623a88ee3593d
sha512: 2808753284d2edf0bc5d7b57cbe4c1c8e2715db344dcd8347af1060c402b940b966a9f67a427efe60a53af2f49f93a1aebf1ace10dd231fcf28473785122ae8b
ssdeep: 6144:icQ3kepigBybL5M41l8FTxqribgpQj880qTe3djDG2Datf5kEOF/59s3CIPjEFwN:icQ3lq5M431r9zjhsC7FxYd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185A48E1A3BCCC927C26D177C54E2A31453F1CA466627EB4B2EF564FE6EB67C40E01292
sha3_384: 1e290c69774fbcba49adce0e1774abe699fdfda9544c31623da7b1092bed72ce496f169e47ed872f4a376a7c042ccea2
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-10-30 12:00:49

Version Info:

Translation: 0x0000 0x04b0
FileDescription: 999
FileVersion: 1.0.0.0
InternalName: 999.exe
LegalCopyright: Copyright © 2015
OriginalFilename: 999.exe
ProductName: 999
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4017168208 also known as:

LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (moderate confidence)
ClamAVWin.Malware.Zusy-9770089-0
CAT-QuickHealBackdoor.MsilFC.S23227530
McAfeeArtemis!606AC0D7CC06
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3e31 )
AlibabaTrojanPSW:MSIL/Gentromal.e30777e9
K7GWTrojan ( 0055e3e31 )
Cybereasonmalicious.7cc06c
BitDefenderThetaGen:NN.ZemsilF.34712.Dq0@ay4DNng
CyrenW32/MSIL_Mintluks.A.gen!Eldorado
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0DCM22
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.MSIL.Agent.fpat
BitDefenderGen:Variant.MSILPerseus.213058
NANO-AntivirusTrojan.Win32.Agent.dyqhui
MicroWorld-eScanGen:Variant.MSILPerseus.213058
APEXMalicious
TencentMsil.Trojan.Agent.Wlze
Ad-AwareGen:Variant.MSILPerseus.213058
SophosGeneric ML PUA (PUA)
ComodoMalware@#1bihqia6lu8ct
DrWebBackDoor.BladabindiNET.17
ZillyaAdware.BrowseFox.Win32.146907
TrendMicroTROJ_GEN.R002C0DCM22
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.606ac0d7cc06cbb2
EmsisoftGen:Variant.MSILPerseus.213058 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.MSIL.amfsm
WebrootW32.Malware.Ml.Vt
AviraTR/PSW.Mintluks.IA
MAXmalware (ai score=85)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPWS:MSIL/Mintluks.A
GDataGen:Variant.MSILPerseus.213058
VBA32Trojan.MSIL.Agent
ALYacGen:Variant.MSILPerseus.213058
MalwarebytesMalware.AI.4017168208
AvastWin32:BotX-gen [Trj]
RisingTrojan.Agent!1.AA0C (CLASSIC)
YandexTrojan.Agent!sxypNUdoe0A
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.U!tr
AVGWin32:BotX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4017168208?

Malware.AI.4017168208 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment