Malware

Malware.AI.4079209936 (file analysis)

Malware Removal

The Malware.AI.4079209936 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4079209936 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4079209936?


File Info:

name: 8C98E9D0325144589090.mlw
path: /opt/CAPEv2/storage/binaries/e913ca8d4d5a37dfafa3a0eb88030f20d9acd0350b9a58fa3cd5a7d3c0c7fe0f
crc32: 118419EF
md5: 8c98e9d03251445890908114a19a7ed3
sha1: f988154e2d403a05cab4930b63f276afae0767ad
sha256: e913ca8d4d5a37dfafa3a0eb88030f20d9acd0350b9a58fa3cd5a7d3c0c7fe0f
sha512: dbff3f010e987b18de44ddcfa342fa2604532ba72fbf9968d478043a4ba85516db9448f3f21117068fc138eabf7941a98705ef6970ae92a945698d4099bf5d33
ssdeep: 12288:TanvjEXTzh5xTqgaKYOALRDeU87Tv56qiEsYCcd0hgSNJYzyXA:wjEfUzKqLRDpUlCcd0imA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AB4231B1B62E8CFC491817015B1BB73FAEA518E010DAF8F9B957B873D604D2055E12F
sha3_384: 77d10c126eadee024bf670a4071dc6bb4748da97641f71c0bbe059a333db4f9497b8d74957426df1a2b890185039fef9
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2019-12-16 00:51:03

Version Info:

0: [No Data]

Malware.AI.4079209936 also known as:

LionicTrojan.Win32.Remcos.m!c
MicroWorld-eScanGen:Variant.Adware.Babar.109
ALYacGen:Variant.Adware.Babar.109
MalwarebytesMalware.AI.4079209936
ZillyaBackdoor.Remcos.Win32.2646
SangforTrojan.Win32.Wacatac.C
K7AntiVirusTrojan ( 0056853f1 )
BitDefenderGen:Variant.Adware.Babar.109
K7GWTrojan ( 0056853f1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Adware.Babar.109
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.EMIB
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Backdoor.Win32.Remcos.gen
AlibabaBackdoor:Win32/Remcos.d23ced5b
NANO-AntivirusTrojan.Win32.Stealer.hlinrm
RisingTrojan.Injector/NSIS!1.CA4F (CLASSIC)
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1228410
DrWebTrojan.PWS.Stealer.28598
VIPREGen:Variant.Adware.Babar.109
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.8c98e9d032514458
EmsisoftGen:Variant.Adware.Babar.109 (B)
IkarusTrojan.Inject
WebrootW32.Trojan.Gen
AviraTR/Injector.nafak
MAXmalware (ai score=65)
MicrosoftTrojan:Win32/Ymacco.AAE9
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataGen:Variant.Adware.Babar.109
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R339911
McAfeeArtemis!8C98E9D03251
VBA32TrojanSpy.Noon
Cylanceunsafe
PandaTrj/CI.A
TencentWin32.Backdoor.Remcos.Vsmw
FortinetW32/EMIB!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.032514
AvastWin32:Evo-gen [Trj]

How to remove Malware.AI.4079209936?

Malware.AI.4079209936 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment