Malware

Malware.AI.4063011407 removal guide

Malware Removal

The Malware.AI.4063011407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4063011407 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4063011407?


File Info:

name: 25E211BAD66E0B0DD260.mlw
path: /opt/CAPEv2/storage/binaries/a4c9ec43d0b0b55fd19efd75179f0572749ad36f6d313c46c07afe7a48178ada
crc32: D9E38177
md5: 25e211bad66e0b0dd260e7ccf07de4c8
sha1: 1f67e69ad305b8f4e2eca7dc5967b4e9ea33d235
sha256: a4c9ec43d0b0b55fd19efd75179f0572749ad36f6d313c46c07afe7a48178ada
sha512: 59326d5582f0fe6db65bddb7561aed116c3a42b2954a8b897b3d8e5e9403900c81f811bc45531b0862be6d959fb8a74f53c2e81cc063fea935eb04c2faa97dd0
ssdeep: 384:Yps55ApwwB4pkdUKqPBixL4YYLwN+BgO26ZsFEcq4D:YE5AuwB4pkdUJPAxLEsFesyc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19992D042AAAA524CE2B64F331152DD273F253FD34E468E2611C47B4F45E3A37F20A619
sha3_384: 75c0f343d4fd052168232afbe9badfbf01be88284af193e90c98ed548662eadb9b20fb711ac19b1c9d58171c815e3b7d
ep_bytes: b824fe40005064ff3500000000648925
timestamp: 2012-04-17 14:04:49

Version Info:

Translation: 0x0804 0x04b0
CompanyName: bohao internet s.l.
ProductName: Starter
FileVersion: 2.96.1230
ProductVersion: 2.96.1230
InternalName: Uninstall
OriginalFilename: Uninstall.exe

Malware.AI.4063011407 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Razy.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Razy.440289
FireEyeGen:Variant.Razy.440289
ALYacGen:Variant.Razy.440289
CylanceUnsafe
SangforTrojan.Win32.Razy.440289
K7GWTrojan ( 004bcce71 )
K7AntiVirusTrojan ( 004bcce71 )
APEXMalicious
BitDefenderGen:Variant.Razy.440289
SUPERAntiSpywareTrojan.Agent/Generic
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Razy.440289
EmsisoftGen:Variant.Razy.440289 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.mc
Trapminemalicious.high.ml.score
SophosGeneric PUA BP (PUA)
IkarusTrojan.Win32.Scar
GDataGen:Variant.Razy.440289
MAXmalware (ai score=82)
ArcabitTrojan.Razy.D6B7E1
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!25E211BAD66E
MalwarebytesMalware.AI.4063011407
TrendMicro-HouseCallTROJ_GEN.R002H09EK22
RisingTrojan.Win32.Generic.1909C6AC (C64:YzY0OielLt0V6s3k)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.78335.susgen
BitDefenderThetaGen:NN.ZevbaCO.34742.bi0fa0i5R8ob
AVGWin32:Malware-gen
Cybereasonmalicious.ad66e0

How to remove Malware.AI.4063011407?

Malware.AI.4063011407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment