Malware

Malware.AI.4057341986 removal guide

Malware Removal

The Malware.AI.4057341986 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4057341986 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

Related domains:

lelemanu.ddns.net
bossbaby.ddns.net

How to determine Malware.AI.4057341986?


File Info:

crc32: CD4AD351
md5: 37856626dec15c899795fd2b5434181c
name: 37856626DEC15C899795FD2B5434181C.mlw
sha1: 9d28d2023e37938fcab342b21370113c1a8f46b4
sha256: b9487ce9b37e55989e22063cb40646c2363b75732d54754e0b3bcc4c1c054797
sha512: acf15fdcbc38a6930c00321575b198ef6d7386605f4d015cbbf48ab9ae9331ea12f6dae47f5c1705095a0008a833320899ca4883cbe107d06e4d5e4bcd18dba2
ssdeep: 49152:LiLFssPH4884H83WI9EGVGb8240mvs0M627Jkr:LiLFtPHJOJ9EFHOJO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
FileVersion: 10,0,16299,15
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10,0,16299,15
FileDescription: Barre Jeu
OriginalFilename: gamepanel.exe.mui
Translation: 0x0409 0x0000

Malware.AI.4057341986 also known as:

K7AntiVirusTrojan ( 0052a64a1 )
LionicTrojan.Win32.Autoit.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.30737841
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.40793
SangforTrojan.Win32.Autoit.sb
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Inject.db58e4b8
K7GWTrojan ( 0052a64a1 )
Cybereasonmalicious.6dec15
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.CAB.AX
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Ototi-6591407-0
KasperskyTrojan.Win32.Autoit.abkum
BitDefenderTrojan.GenericKD.30737841
NANO-AntivirusTrojan.Win32.Generic.fnqvlc
MicroWorld-eScanTrojan.GenericKD.30737841
TencentWin32.Trojan.Autoit.Lknt
Ad-AwareTrojan.GenericKD.30737841
SophosMal/Generic-R + Troj/Inject-CAN
ComodoMalware@#39qpwtok31ms5
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionDropper-FVC!37856626DEC1
FireEyeGeneric.mg.37856626dec15c89
EmsisoftTrojan.GenericKD.30737841 (B)
SentinelOneStatic AI – Malicious PE
AviraDR/Autoit.zxeiw
eGambitUnsafe.AI_Score_60%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.CB9
GDataTrojan.GenericKD.30737841
McAfeeDropper-FVC!37856626DEC1
MAXmalware (ai score=100)
VBA32Trojan.Agentb
MalwarebytesMalware.AI.4057341986
PandaTrj/CI.A
RisingHack.Win32.SpyWare.aa (CLASSIC)
MaxSecureTrojan.Malware.11914803.susgen
FortinetW32/Agent.YMG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4057341986?

Malware.AI.4057341986 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment