Malware

What is “Malware.AI.4081689481”?

Malware Removal

The Malware.AI.4081689481 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4081689481 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.4081689481?


File Info:

name: 24B02E3A9056E06C6FD1.mlw
path: /opt/CAPEv2/storage/binaries/66d0e1659e94bdb24ba31c0df5b75f99153359375e998803413ff948c26b9235
crc32: C8CEC3D0
md5: 24b02e3a9056e06c6fd131a586fcc617
sha1: ab00d6abac9c8a70c50e83d46c6ff227853d97bd
sha256: 66d0e1659e94bdb24ba31c0df5b75f99153359375e998803413ff948c26b9235
sha512: e5161138a031bb561fb49499697b44bc7925574232dcdc07ebc9b074ec27249818416f085ce803c34207f3d71d810a582eb65346aa0e47936076a21e33cd3d7a
ssdeep: 49152:2KYPwY1zXXd7xjkgQCclK6EcoDw4BBIfsNoMXBYRf/m/Pp5QET3VQUN9hC:NYIY1Ld7FkgQCPw4BBxTYRfKPQt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A06AE03B682C0F2D4491A7A51B62B3EAE399B114735CAC3EBE0DD755C711E2A73A34D
sha3_384: 1d35438b8f9f811965014cf0947fe6dbd4df7dde720a0dde51db65273cb3bbe924da72950d3f73b87b11a53493dfca33
ep_bytes: 558bec6aff68a0c0740068b498550064
timestamp: 2022-01-02 18:29:30

Version Info:

FileVersion: 2.6.0.0
FileDescription: 故里非长安出品
ProductName: 客户端
ProductVersion: 2.6.0.0
CompanyName: 2953433131@qq.com
LegalCopyright: 故里非长安出品,仅供技术交流,请勿用于非法用途,违者后果自负,所造成的一切损失与本人无关
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Malware.AI.4081689481 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.NtRootKit.18405
FireEyeGeneric.mg.24b02e3a9056e06c
McAfeeArtemis!24B02E3A9056
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.bac9c8
BitDefenderThetaGen:NN.ZexaF.34114.Nt0@aKWrD5jb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R03BC0DA922
ClamAVWin.Trojan.Agent-360863
KasperskyHEUR:Trojan.Win32.Blamon.gen
AvastWin32:Trojan-gen
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
TrendMicroTROJ_GEN.R03BC0DA922
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Spy.KrBanker.HS7VX2
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.4081689481
APEXMalicious
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazqxR/uXPJYT2O6Enkez9i62)
IkarusTrojan.Win32.Agent
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Malware.AI.4081689481?

Malware.AI.4081689481 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment