Malware

What is “Malware.AI.4027394861”?

Malware Removal

The Malware.AI.4027394861 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4027394861 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.4027394861?


File Info:

name: 17EF0CDF22DCA48931A5.mlw
path: /opt/CAPEv2/storage/binaries/f8593bc1c31f21e2155bfc585ed1aabc269a9b3bc11301eb4060fc255b57e55a
crc32: E410689E
md5: 17ef0cdf22dca48931a5aa721ed857c3
sha1: feb0f7c31bd889fd9c17490959002e8e0016c13a
sha256: f8593bc1c31f21e2155bfc585ed1aabc269a9b3bc11301eb4060fc255b57e55a
sha512: 5b862a9bddff97bba11fa1daaf58313d8da12fbc28e4f0c0e1a8e8e704a212b92ce3f97df5f9e9b5a67ea35700a2c0f629bdd0c685e5d1c428c8498b570b9d05
ssdeep: 6144:RerCmq/kHlnGRBFUnDdPSagst1cW4O1xOy38N:IrCmnHsUnJ/XBKN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A249D2372C9C879D1AA16B36DC0B3778533F8B02E21653772D48DDC6DB5672A8219B3
sha3_384: f46b2a8939ee766799c86680a68ea65c11c158ce5487f6bbbc638f66303f6abfb7871461c6a823730b1ace7f5bd2b331
ep_bytes: e890030000e936fdffff6a1468f03c41
timestamp: 2015-04-24 10:26:48

Version Info:

FileDescription: Universal Cheat
FileVersion: 1, 0, 0, 12
InternalName: UNICHEAT
LegalCopyright: (c) 2015 V10 (http://v10.name)
LegalTrademarks: (c) 2015 V10 (http://v10.name)
OriginalFilename: UNICHEAT.EXE
ProductName: Uni Cheat
ProductVersion: 1, 0, 0, 12
Translation: 0x0800 0x04b0

Malware.AI.4027394861 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Razy.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.717578
FireEyeGeneric.mg.17ef0cdf22dca489
McAfeePUP-XBI-MK
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 004ee1021 )
K7GWUnwanted-Program ( 004ee1021 )
Cybereasonmalicious.f22dca
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/GameHack.AHY potentially unsafe
APEXMalicious
AvastWin32:Evo-gen [Susp]
BitDefenderGen:Variant.Razy.717578
Ad-AwareGen:Variant.Razy.717578
SophosUniversal Cheat (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dh
EmsisoftGen:Variant.Razy.717578 (B)
Paloaltogeneric.ml
GDataGen:Variant.Razy.717578
Antiy-AVLTrojan/Generic.ASMalwS.252050F
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4711782
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.mu1@a0DfWofk
ALYacGen:Variant.Razy.717578
MAXmalware (ai score=86)
VBA32BScope.Trojan.Click
MalwarebytesMalware.AI.4027394861
TrendMicro-HouseCallTROJ_GEN.R03BH06L221
RisingMalware.Heuristic!ET#95% (RDMK:cmRtazrc17tg2en41X6n4SZaqb+w)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/GameHack
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.4027394861?

Malware.AI.4027394861 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment