Malware

Malware.AI.4038884991 information

Malware Removal

The Malware.AI.4038884991 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4038884991 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4038884991?


File Info:

name: 0F345E9D6217DF6CD123.mlw
path: /opt/CAPEv2/storage/binaries/fd0c8fd688df9fc3ad787c5a93ca9574029b0362fedd15f47c49e3f076a5b2e2
crc32: 9904F29A
md5: 0f345e9d6217df6cd123956c727c8f6b
sha1: c1f16f2c72778728d6373fe3c193729f51cb9f02
sha256: fd0c8fd688df9fc3ad787c5a93ca9574029b0362fedd15f47c49e3f076a5b2e2
sha512: c5a3e998574eaee34bbb38af5923ddd93866ffb469db6f143fcc33f19ca59b331dab25de913fa73d167ce6aaef9c0fcf0d0b86df2f248357d69847ebc1b0ea9d
ssdeep: 12288:hoeCFRfmwHI/OfKhU7BI6mYbgieWlej2nlMUQuiB1U:hWfffI/Ofd7BSqg+plMUQuk2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FEF48D26B690C837C162363D8D0AD7B89929BF843E2459463FF53E4DAF3D7423925287
sha3_384: 50cc2aad1c41be019c03553f99c5d523e6ca8582aaa715a98687cd79febded00aadfcca0bbc3f073cd06754beda55bc8
ep_bytes: 558bec83c4f0b854364500e8c824fbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.4038884991 also known as:

LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.MulDrop4.29862
MicroWorld-eScanGen:Variant.Delf.150
CAT-QuickHealRansom.Weenloc.A8
ALYacGen:Variant.Delf.150
MalwarebytesMalware.AI.4038884991
VIPREGen:Variant.Delf.150
SangforTrojan.Win32.Blocker.buxin
AlibabaRansom:Win32/Blocker.607b9531
ArcabitTrojan.Delf.150
BitDefenderThetaGen:NN.ZelphiF.36132.SGW@aaLbhZcc
VirITTrojan.Win32.Generic.BWXI
SymantecTrojan.Gen
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.awpe
BitDefenderGen:Variant.Delf.150
NANO-AntivirusTrojan.Win32.Blocker.bmynec
AvastWin32:Malware-gen
RisingMalware.Undefined!8.C (TFE:4:LvyQrpw7erS)
EmsisoftGen:Variant.Delf.150 (B)
F-SecureTrojan.TR/LockScreen.BW.480
ZillyaTrojan.Blocker.Win32.6854
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.bh
FireEyeGen:Variant.Delf.150
SophosMal/Generic-S
IkarusTrojan-Ransom.Blocker
AviraTR/LockScreen.BW.480
MAXmalware (ai score=85)
XcitiumMalware@#3qqtktsszdbjv
MicrosoftRansom:Win32/LockScreen.BW
ZoneAlarmTrojan-Ransom.Win32.Blocker.awpe
GDataGen:Variant.Delf.150
GoogleDetected
McAfeeArtemis!0F345E9D6217
VBA32Trojan.Boot.Heur
Cylanceunsafe
PandaGeneric Malware
TencentWin32.Trojan.Blocker.Agow
YandexTrojan.GenAsa!NdXSXIFzOvE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.AWPE!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.4038884991?

Malware.AI.4038884991 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment