Malware

Malware.AI.4076035077 removal guide

Malware Removal

The Malware.AI.4076035077 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4076035077 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.4076035077?


File Info:

name: AD4F4ECD3A52718970DF.mlw
path: /opt/CAPEv2/storage/binaries/002cd04f6a1e5ab71dbb988ccd0d1b6e5520b12bcfa62018eea2bc54660bfed3
crc32: 1A80563C
md5: ad4f4ecd3a52718970df68862d673307
sha1: 0b536db7b3638e9f7cfab03ef47a94b22f17462a
sha256: 002cd04f6a1e5ab71dbb988ccd0d1b6e5520b12bcfa62018eea2bc54660bfed3
sha512: 3165a5a0b99f2f2b2a253511bfa4d5fb65340fd85bf3a2b8b5d24ccf9ede44d00f75e3ba43fc865b5aa2cc5256cdd7b04d73b73b82025e56a3a75a84d02630fd
ssdeep: 6144:Yf6I+2JR8XiO9PmUUb1AsJbL4nAwCKcn3yLq2SYZs:W6I+2f8ZP/USyInAwoniBD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E6412826D5E9B1DEF05A07DEFD143C511C655B1173A6AE3BB086F27B8E8790036EA0C
sha3_384: 9c7647117bdc1d648bfd0269c30a5b494d35631dd00416d5322c8b944be6867681f0c272d4effdf7f3cca2171a40bcc8
ep_bytes: 7400e9b3ee0400000000000000000000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.4076035077 also known as:

LionicWorm.Win32.Generic.l60F
MicroWorld-eScanGen:Trojan.Heur.sKalr1cX3FnG
FireEyeGeneric.mg.ad4f4ecd3a527189
McAfeeArtemis!AD4F4ECD3A52
CylanceUnsafe
ZillyaTrojan.Cakl.Win32.56
K7AntiVirusTrojan ( 004bf92f1 )
K7GWTrojan ( 004bf92f1 )
Cybereasonmalicious.d3a527
ArcabitTrojan.Heur.sKalr1cX3FnG
CyrenW32/Hupigon.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Cakl.NAT
ZonerProbably Heur.ExeHeaderP
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Cakl.bfj
BitDefenderGen:Trojan.Heur.sKalr1cX3FnG
NANO-AntivirusTrojan.Win32.Cakl.fhvvy
AvastWin32:VB-FFN [Trj]
TencentWin32.Backdoor.Cakl.Kzfl
Ad-AwareGen:Trojan.Heur.sKalr1cX3FnG
TACHYONBackdoor/W32.Cakl.306688.B
SophosMal/Behav-103
ComodoBackdoor.Win32.Cakl.~dy01@3kchnd
DrWebTrojan.PWS.Legmir.2026
VIPREGen:Trojan.Heur.sKalr1cX3FnG
McAfee-GW-Editiongeneric!bg.n
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Heur.sKalr1cX3FnG (B)
JiangminBackdoor/Cakl.qb
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASCommon.160
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.sKalr1cX3FnG
GoogleDetected
AhnLab-V3Trojan/Win32.QQRob.R5699
BitDefenderThetaAI:Packer.2AEB3E7F1C
ALYacGen:Trojan.Heur.sKalr1cX3FnG
MAXmalware (ai score=80)
VBA32Win32.Trojan.Dropper.Heur
MalwarebytesMalware.AI.4076035077
RisingBackdoor.Cakl!8.AFD (CLOUD)
YandexTrojan.Cakl!kPh5TU7tcak
IkarusBackdoor.Win32.Cakl
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cakl.ANV!tr
AVGWin32:VB-FFN [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.4076035077?

Malware.AI.4076035077 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment