Malware

Malware.AI.4036913060 (file analysis)

Malware Removal

The Malware.AI.4036913060 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4036913060 virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Detects VirtualBox through the presence of a library
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file

How to determine Malware.AI.4036913060?


File Info:

crc32: 6FE420F1
md5: 03af683ad11a611eac901a492eb582fe
name: 03AF683AD11A611EAC901A492EB582FE.mlw
sha1: 7c67a8a5e50c76589723aa3d51fc7add53fb917d
sha256: f8f4e57c931deb63ff0746c290543f108939375a8f36f0a518dbddc7a52f4263
sha512: 095d52147c245c7b04d7166939b4cdfd09246bc1415b2296e2b9b910092df0c889653e963b8aacf44e989afbcdfa7d1215e728ea36811b712b3c21624fdf8c0c
ssdeep: 24576:hxaVxr59+k4FobGlgaeFvdOWHBFjyJWC6Sz3VXEqdxGZD+GxiwKtl:hhjoKzexdB3yHD5vkniwK3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4036913060 also known as:

MicroWorld-eScanTrojan.Uztuby.9
FireEyeTrojan.Uztuby.9
ALYacTrojan.Agent.CEXY
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00508ca71 )
BitDefenderTrojan.Uztuby.9
K7GWTrojan ( 00508ca71 )
Cybereasonmalicious.ad11a6
SymantecBackdoor.Graybird
ESET-NOD32multiple detections
APEXMalicious
AvastVBS:Agent-BRQ [Trj]
ClamAVWin.Trojan.RC465-5900681-0
KasperskyTrojan.Win32.Inject.wnhc
NANO-AntivirusTrojan.Win32.DMNU.emoakh
TencentWin32.Trojan.Inject.Eyp
Ad-AwareTrojan.Uztuby.9
EmsisoftTrojan.Uztuby.9 (B)
F-SecureMalware.VBS/Shellcode.ooina
ZillyaTrojan.Agent.Win32.763556
TrendMicroTROJ_INJECTOR_GC170023.UVPM
McAfee-GW-EditionGenericRXBC-WU!61E081AB45D1
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
JiangminTrojan.Inject.xib
AviraVBS/Shellcode.ooina
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Inject.WN.(kcloud)
MicrosoftHackTool:Win32/AutoKMS!ml
ArcabitTrojan.Agent.CEXY
ZoneAlarmTrojan.Win32.Inject.wnhc
GDataTrojan.Agent.CEXY
CynetMalicious (score: 85)
McAfeeArtemis!03AF683AD11A
VBA32Trojan.Inject
MalwarebytesMalware.AI.4036913060
PandaTrj/CI.A
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_INJECTOR_GC170023.UVPM
RisingTrojan.Inject!8.103 (TFE:5:cLws4IBqv5T)
YandexTrojan.GenAsa!zlp0JEM+YUY
MAXmalware (ai score=81)
FortinetW32/Generic.AC.3E0BE6
AVGVBS:Agent-BRQ [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.ec3

How to remove Malware.AI.4036913060?

Malware.AI.4036913060 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment