Malware

Malware.AI.4047015986 (file analysis)

Malware Removal

The Malware.AI.4047015986 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4047015986 virus can do?

  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Malware.AI.4047015986?


File Info:

name: 35BFEEAD4F4101E5DBD0.mlw
path: /opt/CAPEv2/storage/binaries/1a20939850814b30118ac4175bbe6e06da111fb480cbce98be7a815d382d3853
crc32: F6368317
md5: 35bfeead4f4101e5dbd0a3efccd6d5e1
sha1: 8033ac0709fa6470fda09ab3211be8dc4887f637
sha256: 1a20939850814b30118ac4175bbe6e06da111fb480cbce98be7a815d382d3853
sha512: 486e5f6fe3bf37133be1f28d5f1cd45233f45d568bdef09b41a685c9a3ca1625baf14cfb6d33d97418eb99a8def17b27f91df5b378888b132b739d5223a11293
ssdeep: 6144:LD+8Zu+ArJ8tDzPMnNOZa2bOd4RXdfY8L7RELu/WOcPf7SLrHm8erQ45b:LYdd4T/KUzm8erQW
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1BA84F84A194A6D26F89044791283BB214DDDBC432283225BA6DFF3562BF3BDEF8575C0
sha3_384: abbc64d363748826018e6e95ac02c3b6d8c7d8b8d11bdb4a830b3289db9d5ff664d25956e296ba161eebdfa82afc444a
ep_bytes: 40534883ec20488bd9e88a050000488b
timestamp: 2100-03-02 06:33:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Client Server Runtime Process
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: CSRSS.Exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: CSRSS.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Malware.AI.4047015986 also known as:

LionicTrojan.Win32.Bulz.4!c
MicroWorld-eScanGen:Variant.Bulz.875241
FireEyeGen:Variant.Bulz.875241
McAfeeArtemis!35BFEEAD4F41
MalwarebytesMalware.AI.4047015986
CyrenW64/Ipamor.CZ.gen!Eldorado
Paloaltogeneric.ml
ClamAVWin.Dropper.Zusy-9857958-0
BitDefenderGen:Variant.Bulz.875241
AvastWin64:Malware-gen
Ad-AwareGen:Variant.Bulz.875241
EmsisoftGen:Variant.Bulz.875241 (B)
GDataGen:Variant.Bulz.875241
Antiy-AVLTrojan/Generic.ASVirus.302
GridinsoftRansom.Win64.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.875241
MAXmalware (ai score=87)
MaxSecureTrojan.Malware.121218.susgen
FortinetW64/Bulz.9212!tr
AVGWin64:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Malware.AI.4047015986?

Malware.AI.4047015986 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment