Malware

About “Malware.AI.4046975578” infection

Malware Removal

The Malware.AI.4046975578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4046975578 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • CAPE detected the PyInstaller malware family

How to determine Malware.AI.4046975578?


File Info:

name: EDAACB7D3B4F5957F111.mlw
path: /opt/CAPEv2/storage/binaries/fd9d704443804eb9b11917dc55275dc0888b8579727f01fac186f0baf1dc1b2f
crc32: 73C63150
md5: edaacb7d3b4f5957f11187b5c6b2d033
sha1: 91190beff37e11abc5dd89a291061b252e2203bb
sha256: fd9d704443804eb9b11917dc55275dc0888b8579727f01fac186f0baf1dc1b2f
sha512: f5c48102647d59eaf4b51bcc186f787c6f7ef2e8b9522e814f583700f859631d8c93d2db141e0d8375a4fca012323d2651ef125cd9d2a0ed6e06bc152fdd10f9
ssdeep: 393216:qXOIe2MVh6/NnKD262ve7zeKLpD2WammTmQSF9crPKtM8gY:q+wMX852bqSe41jammocrPKt4Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15DF63302FED054E1CBC1203B1B966F00F4AD75929A119AEE13A5FF8FD9239A1CE31795
sha3_384: 5725c4da21571881eae573e4c7dbdf512a34660431149ae76013a9316823fc37f1dc70d9bcbaef339d2389b40f60999c
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Malware.AI.4046975578 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.edaacb7d3b4f5957
CylanceUnsafe
SangforTrojan.Win32.Agent.Vpd1
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Generic.ceedbe3c
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.BCVVXOX
Paloaltogeneric.ml
ClamAVWin.Malware.Fugrafa-9938779-0
KasperskyHEUR:Trojan.Win32.Generic
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generik.Anzm
ComodoHeur.Dual.Extensions@1z141z3
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S (PUA)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R478670
Acronissuspicious
McAfeeArtemis!EDAACB7D3B4F
MalwarebytesMalware.AI.4046975578
APEXMalicious
AVGWin32:Trojan-gen
Cybereasonmalicious.ff37e1

How to remove Malware.AI.4046975578?

Malware.AI.4046975578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment