Malware

Malware.AI.4057848279 malicious file

Malware Removal

The Malware.AI.4057848279 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4057848279 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4057848279?


File Info:

name: 39ED350F3B69FB99F8D7.mlw
path: /opt/CAPEv2/storage/binaries/e55d437160f132dfb8ba063eee1137de9d10714f24d08ed4a32caab11f288e84
crc32: 332DDE0F
md5: 39ed350f3b69fb99f8d7ac04f69ed218
sha1: 61ece7f99b283e8f68f6d1327e94128f1250622c
sha256: e55d437160f132dfb8ba063eee1137de9d10714f24d08ed4a32caab11f288e84
sha512: c1165d3b829f33a223503aca774ad617aafc5cc535bef1d6ade84580a27e1e28ff8f02801587d91180d5ce42c6a5730fa2029100f04385003849be4bad1363b3
ssdeep: 49152:M77P0+/7SsT4bjDTdfE2WCWZfzrvjmyOhnG/JzSVbiI2fc:N+/0FE249zrvjy628h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4166B66E1585223E12FD9705CB70BCC5134FFB22A147B0A21F93E98AFF57D1B90A14A
sha3_384: 313f88917d1e20548e45cc858edf29e75c8be7ad363a39f351d1a7822db2e2da32d8f5ae05417f477cf588b457449d09
ep_bytes: 558bec83c4f0b878a64c00e828c1f3ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.4057848279 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.85799
FireEyeGeneric.mg.39ed350f3b69fb99
ALYacGen:Variant.Bulz.85799
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
BaiduWin32.Trojan-GameThief.Lmir.b
VirITTrojan.Win32.Atros3.AFAY
APEXMalicious
BitDefenderGen:Variant.Bulz.85799
AvastWin32:Delf-UAF [Trj]
TencentMalware.Win32.Gencirc.114b4d22
Ad-AwareGen:Variant.Bulz.85799
EmsisoftGen:Variant.Bulz.85799 (B)
F-SecureTrojan.TR/Spy.Banker.Gen2
ZillyaTrojan.Generic.Win32.577
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
SophosMal/GamePSW-C
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.85799
AviraTR/Spy.Banker.Gen2
MAXmalware (ai score=85)
ArcabitTrojan.Bulz.D14F27
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.HQJ.R481253
McAfeeGenericR-HQJ!39ED350F3B69
VBA32Trojan.Wacatac
MalwarebytesMalware.AI.4057848279
RisingMalware.Undefined!8.C (RDMK:cmRtazo4NJTuHLm/564siSiLweu2)
YandexTrojanSpy.Banker!PHp1J9GnAgQ
IkarusTrojan-GameThief.Win32.Lmir
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZelphiF.34742.@JZ@a0CT9Eoj
AVGWin32:Delf-UAF [Trj]
Cybereasonmalicious.f3b69f
PandaTrj/Genetic.gen

How to remove Malware.AI.4057848279?

Malware.AI.4057848279 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment