Malware

What is “Malware.AI.4060020939”?

Malware Removal

The Malware.AI.4060020939 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4060020939 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4060020939?


File Info:

crc32: 660DBE15
md5: b3b48a06fb55557b797dadfe6e556a0e
name: B3B48A06FB55557B797DADFE6E556A0E.mlw
sha1: 4cc59f5e0feec3716a9f386fd9237633a175a4a6
sha256: 70ec1b38321516561820c6397487dff9f605cbe0c319df1b14a4b46602d806e9
sha512: e8a4a5c7f8ad238b27612e0e824540b52eff47cdfd9ba8daca48b3d42b57e08c964ce9f36b3c1e06abf78b3d98ce9ed2541f1d25f2f547f1f989fdcdee760f7a
ssdeep: 1536:AjXkPt17AhdS2FbmZKr6reD8vLYW64ZcoUxzHTZiaJwjB:Aj0PtyS2FbwKurC8vU4ZKxzHwa6l
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013 Nero AG and its licensors
InternalName: NeroDisc
FileVersion: 15,0,25,0
CompanyName: Nero AG
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: NeroDiscMergeWrongDisc
SpecialBuild: 15,0,25,0
ProductVersion: 15,0,25,0
FileDescription: NeroDiscMergeWrongDisc Application
OriginalFilename: NeroDiscMergeWrongDisc.exe
Translation: 0x0409 0x04e4

Malware.AI.4060020939 also known as:

K7AntiVirusTrojan ( 0051e0631 )
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.MUE.A6
ALYacGen:Variant.Zusy.319338
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0051e0631 )
Cybereasonmalicious.6fb555
CyrenW32/S-2af32512!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.DPXE
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.319338
NANO-AntivirusTrojan.Win32.Kryptik.evqozp
MicroWorld-eScanGen:Variant.Zusy.319338
TencentMalware.Win32.Gencirc.10b6a4b9
Ad-AwareGen:Variant.Zusy.319338
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.fy0@aaICsqei
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.Pate.nh
FireEyeGeneric.mg.b3b48a06fb55557b
EmsisoftGen:Variant.Zusy.319338 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1110705
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22ED01C
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Zusy.D4DF6A
GDataGen:Variant.Zusy.319338
AhnLab-V3Trojan/Win32.CryptXXX.R185958
Acronissuspicious
McAfeeRansomware-GJA!B3B48A06FB55
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.4060020939
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.100 (RDML:573vfS4opDRmIZ0LmnosPQ)
YandexTrojan.GenAsa!ao0N/xdCg2Q
IkarusTrojan-Ransom.Locky
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4060020939?

Malware.AI.4060020939 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment