Malware

Malware.AI.4079426671 (file analysis)

Malware Removal

The Malware.AI.4079426671 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4079426671 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Malware.AI.4079426671?


File Info:

name: AA3EF6DB22D541DF7375.mlw
path: /opt/CAPEv2/storage/binaries/0ad11df1ffc4ddbf12154edbdc95b5b2a4ee494f94f7c0fb423259308670bd1f
crc32: 89CF3147
md5: aa3ef6db22d541df737591f6235f9d63
sha1: ee8e01ef70332eb91539e59835a6f084ed87fd98
sha256: 0ad11df1ffc4ddbf12154edbdc95b5b2a4ee494f94f7c0fb423259308670bd1f
sha512: 0aec271da6e0553143764985e0676c8ce041feb571f83e27be8e8017f3b8c2d102d4e2e62cb6f81509160590a0a318c9eb2042c9d0b4b0cda24279ccae937895
ssdeep: 24576:Eal7omHpdG7+iWM2TEOriw+EMOqLqFPYkwqXlj/HwQPcWf2+eZCS:zl7zG77WZI0+EMOquFQkwqWX5H4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A4451223F8C3E073C65AC235A56DDDE562323AD6316F491C034D2F4EFE72BA1AA95481
sha3_384: 2d5726025b03f50fbfe329e5c2a5470c1b7f015fe9249f163c94d783c8e9721a9241818c3c0961deb6df4f1c915eae82
ep_bytes: e802420000e995feffff8bff558bec83
timestamp: 2018-02-06 13:20:31

Version Info:

CompanyName: CrowdStrike, Inc.
FileDescription: CrowdStrike Forensics Data Collection Tool
FileVersion: 1.0.201.0
InternalName: FalconForensicsCollector.exe
LegalCopyright: Copyright (C) CrowdStrike, Inc. 2017. All rights reserved.
OriginalFilename: FalconForensicsCollector.exe
ProductName: CrowdStrike Falcon Forensics - Collector
ProductVersion: 1.0.201.0
Translation: 0x0409 0x04b0

Malware.AI.4079426671 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.38189806
FireEyeGeneric.mg.aa3ef6db22d541df
McAfeeArtemis!AA3EF6DB22D5
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Vidro.b531a293
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
ClamAVWin.Trojan.SK-3
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.38189806
AvastWin32:Agent-AAKC [Trj]
TencentMalware.Win32.Gencirc.10c99e90
Ad-AwareTrojan.GenericKD.38189806
SophosMal/Generic-S
ZillyaTrojan.Generic.Win32.1360344
TrendMicroTROJ_GEN.R002C0WL721
McAfee-GW-EditionBehavesLike.Win32.Drixed.tc
EmsisoftTrojan.GenericKD.38189806 (B)
GDataTrojan.GenericKD.38189806
JiangminTrojan.Yakes.xfp
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.Yakes.C2395769
ALYacTrojan.GenericKD.38189806
VBA32Trojan.Sabsik.FL
MalwarebytesMalware.AI.4079426671
TrendMicro-HouseCallTROJ_GEN.R002C0WL721
RisingTrojan.Generic@ML.99 (RDMK:ExMhTaGr7I7KzuV/K5MHnQ)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Agent-AAKC [Trj]
PandaTrj/CI.A

How to remove Malware.AI.4079426671?

Malware.AI.4079426671 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment