Malware

Should I remove “Malware.AI.404806960”?

Malware Removal

The Malware.AI.404806960 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.404806960 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

hi.baidu.com
infoflow.baidu.com
ocsp.globalsign.com
ocsp2.globalsign.com
crl.globalsign.com

How to determine Malware.AI.404806960?


File Info:

crc32: 212B8BF2
md5: 93cd4ebc72cb05a3b1fc2bde6c1c3838
name: 93CD4EBC72CB05A3B1FC2BDE6C1C3838.mlw
sha1: 097de8aa32c6dc26a38faa7e5521b88fe85e2d3d
sha256: cb549192a82caf9d7e756e377672219da0d1a34b9bb295028720e5541aa042bf
sha512: 00d4dcc7cf90864cad71a18672cd34c810a414d0eec49cc33745dbad49ec3a074fb83384c30c1e7158e133ea10590b87898a0f1331ecad9472018659a9b274df
ssdeep: 12288:vb5V9mB1grTQyiFTHFvNZKDs8cZRpqGjm2K010IIQhwYfc+oa:NV9c67iFTlv+5cjtHK010IIQfvo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 1984-2008 Adobe Systems Incorporated and its licensors. All rights reserved.
FileVersion: 9.0.0.2008061200
CompanyName: Adobe Systems Incorporated
Comments:
ProductName: Adobe Acrobat
ProductVersion: 9.0.0.2008061200
FileDescription: Adobe Acrobat SpeedLauncher
OriginalFilename: AcroSpeedLaunch.exe
Translation: 0x0409 0x04e4

Malware.AI.404806960 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056d5f51 )
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Siggen.54
MicroWorld-eScanGen:Trojan.ProcessHijack.O81@ayNDlHai
ALYacGen:Trojan.ProcessHijack.O81@ayNDlHai
CylanceUnsafe
ZillyaTrojan.Ren.Win32.1387
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Trojan.ProcessHijack.O81@ayNDlHai
K7GWTrojan ( 0056d5f51 )
Cybereasonmalicious.c72cb0
CyrenW32/S-cd850ca2!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.IW
APEXMalicious
ClamAVWin.Malware.Explorerhijack-6980684-0
KasperskyHEUR:Trojan.Win32.Diple.vho
TencentTrojan.Win32.Diple.zb
Ad-AwareGen:Trojan.ProcessHijack.O81@ayNDlHai
SophosML/PE-A + Troj/Patched-BS
ComodoHeur.Corrupt.PE@1z141z3
BitDefenderThetaGen:NN.ZexaF.34058.O81@ayNDlHai
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jc
FireEyeGeneric.mg.93cd4ebc72cb05a3
EmsisoftGen:Trojan.ProcessHijack.O81@ayNDlHai (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Ren.Gen
eGambitUnsafe.AI_Score_70%
Antiy-AVLTrojan/Generic.ASBOL.C5A5
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.ProcessHijack.E6CBBC
GDataGen:Trojan.ProcessHijack.O81@ayNDlHai
AhnLab-V3Trojan/Win32.Tiggre.R235674
Acronissuspicious
McAfeeTrojan-FPZU!93CD4EBC72CB
MAXmalware (ai score=87)
VBA32Trojan.Tnega
MalwarebytesMalware.AI.404806960
RisingTrojan.Patched!1.B352 (CLASSIC)
IkarusTrojan.Win32.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IW!tr

How to remove Malware.AI.404806960?

Malware.AI.404806960 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment