Malware

What is “Malware.AI.4080945026”?

Malware Removal

The Malware.AI.4080945026 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4080945026 virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
2no.co
apps.identrust.com

How to determine Malware.AI.4080945026?


File Info:

crc32: 3A1B4973
md5: c67d48f1eb52c9fee9da15ca3a848b13
name: C67D48F1EB52C9FEE9DA15CA3A848B13.mlw
sha1: b6ec7bb486767bf139a31a2d032b2c58983399c5
sha256: af0d62ecd9bcdde3f9d71c43c354adc96f09d46e676768f8889f98dc9e4308d2
sha512: a2f8dd3ffb381cb47d0481f0299c41718cc02ccecc455a023642ef3b83914aa73fdb98242890ab4bbf26355f6b3d924de101ecdeac28e64856fbd2b2ba3a2e7a
ssdeep: 393216:EYEJOsf2kcdMjXHpvHMgN9j2bLZjR4o56jMTW:VEJT2E7pvsgNd2bLZjR4BF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.4080945026 also known as:

K7AntiVirusTrojan ( 005411551 )
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.AutoIt.MineDropper.C
ALYacAdware.GenericKD.36967488
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojanDropper:AutoIt/Nymeria.8c468723
K7GWTrojan ( 005411551 )
Cybereasonmalicious.1eb52c
CyrenW32/Nymeria.L.gen!Eldorado
SymantecPUA.AutoItDropper
ESET-NOD32a variant of Win32/TrojanDropper.Autoit.TL
APEXMalicious
AvastBV:Mykings-N [Trj]
ClamAVWin.Malware.Reline-9864707-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderAdware.GenericKD.36967488
MicroWorld-eScanAdware.GenericKD.36967488
Ad-AwareAdware.GenericKD.36967488
SophosGeneric PUA LG (PUA)
BitDefenderThetaAI:Packer.BC75735117
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DEP21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.c67d48f1eb52c9fe
EmsisoftAdware.GenericKD.36967488 (B)
AviraDR/AutoIt.Gen
eGambitUnsafe.AI_Score_73%
MicrosoftTrojanDropper:AutoIt/Nymeria.AR!MTB
GDataWin32.Trojan.BSE.196N20V
AhnLab-V3Malware/Win32.RL_Generic.R302719
McAfeeArtemis!C67D48F1EB52
MAXmalware (ai score=62)
VBA32TrojanDropper.AutoIt.Nymeria
MalwarebytesMalware.AI.4080945026
TrendMicro-HouseCallTROJ_GEN.R002C0DEP21
RisingTrojan.CoinMiner/Autoit!1.C937 (CLASSIC)
IkarusTrojan-Dropper.Win32.Autoit
FortinetAutoIt/CoinMiner.TL!tr
AVGBV:Mykings-N [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.4080945026?

Malware.AI.4080945026 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment