Malware

About “Malware.AI.4064829693” infection

Malware Removal

The Malware.AI.4064829693 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4064829693 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • NtSetInformationThread: attempt to hide thread from debugger
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools

How to determine Malware.AI.4064829693?


File Info:

name: 7C1B0FB71E297FD3F5C6.mlw
path: /opt/CAPEv2/storage/binaries/9ab603f2fc54274106e251c180554090d35e3f00e2e638931c14d92c1d1c39f3
crc32: B7F4595F
md5: 7c1b0fb71e297fd3f5c6dd529fee8fa9
sha1: 66bc40204bb11772c40ee41a00491af9e0a08973
sha256: 9ab603f2fc54274106e251c180554090d35e3f00e2e638931c14d92c1d1c39f3
sha512: 89a5e7410a967ebe4572930873b874cafeb401220fafb24f525cd9d09220575619dca8811e7397dd81040a2862e8c343ec28d0f8730f61105045f039f5d9cc0a
ssdeep: 24576:crdwnkIwbxELgAZKsmRMsenZazM3JuujZE4dY/sQT6DC:cmnk9Iufez3J5doYD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18585B050D1429D24C6E02876993D6FF12463E8757F9870F3E1E4492BAEAF2C0E297397
sha3_384: 9506339acb33cc3dcda0391d0e80351c9de1ed2820ef89595d1e86a7d90d7bb121d5312770f42464861dceed2dbe59fa
ep_bytes: e8a9050000e974feffff558bec6a00ff
timestamp: 2021-11-22 21:09:14

Version Info:

0: [No Data]

Malware.AI.4064829693 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.7c1b0fb71e297fd3
McAfeeArtemis!7C1B0FB71E29
SymantecML.Attribute.HighConfidence
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosGeneric ML PUA (PUA)
GridinsoftRansom.Win32.Wacatac.sa
APEXMalicious
CynetMalicious (score: 100)
MalwarebytesMalware.AI.4064829693
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove Malware.AI.4064829693?

Malware.AI.4064829693 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment