Malware

Malware.AI.4084778638 malicious file

Malware Removal

The Malware.AI.4084778638 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4084778638 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Hebrew
  • Authenticode signature is invalid
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

How to determine Malware.AI.4084778638?


File Info:

name: 9CF81A312EA162DB1BAA.mlw
path: /opt/CAPEv2/storage/binaries/511e1bcc41a31ee030e5c38920ce0151f67316fdbf05cb8143a4cbcd0e1dba83
crc32: FD0C9226
md5: 9cf81a312ea162db1baa1e9fce30e56f
sha1: 11f41f7da676cfbc7ab3c95326c355ab192fd98b
sha256: 511e1bcc41a31ee030e5c38920ce0151f67316fdbf05cb8143a4cbcd0e1dba83
sha512: 7d9aa707dea11402a66bfbcf4a1d77b244a0ab81a16afb8b950d4d391f5476c2491279a1f38ace69a76f82258c9e329a71e3f74403768df3bc7d4b6812ccc12d
ssdeep: 6144:K4owLyn4p7Az4ADTMNy1gffIKkiwBQRsv3:towLy4p7AMCINy+ffIKkiX63
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178649F017291C037D4A340F7496A8739DA7E79622B1675C7BFC40EAD5F14AE2AB3270A
sha3_384: 5bd27c213e4deee8e052eab79ecfe3a9a3483d145ba4ecdd300d485d5340e752e836fdaa0bdb90cff34d1d19b962efd5
ep_bytes: e8488f0000e916feffff558bec837d08
timestamp: 2012-01-26 13:08:29

Version Info:

CompanyName: Random-Logic
FileDescription: Installer
FileVersion: 3, 7, 0, 17
InternalName: Installer
LegalCopyright: Copyright © 2004
OriginalFilename: Installer.exe
ProductName: Random-Logic Installer
ProductVersion: 3, 7, 0, 17
Translation: 0x0409 0x04b0

Malware.AI.4084778638 also known as:

LionicTrojan.Win32.Agent.tod9
MicroWorld-eScanTrojan.GenericKD.39296081
FireEyeTrojan.GenericKD.39296081
ALYacTrojan.GenericKD.39296081
MalwarebytesMalware.AI.4084778638
VIPRETrojan.GenericKD.39296081
BitDefenderTrojan.GenericKD.39296081
VirITTrojan.Win32.DownLoader13.YPE
CyrenW32/S-5eebcffe!Eldorado
SymantecTrojan.Gen
TrendMicro-HouseCallTROJ_GEN.R002H0CF822
RisingTrojan.Generic@AI.90 (RDML:J8QqDjPgr52/GFh3xDdvRg)
Ad-AwareTrojan.GenericKD.39296081
SophosGeneric ML PUA (PUA)
DrWebTrojan.DownLoader13.16618
ZillyaAdware.BrowseFox.Win32.255030
McAfee-GW-EditionGenericRXAU-VO!9CF81A312EA1
EmsisoftTrojan.GenericKD.39296081 (B)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2579C51
GDataTrojan.GenericKD.39296081
McAfeeGenericRXAU-VO!9CF81A312EA1
VBA32suspected of Trojan.Downloader.gen
CylanceUnsafe
YandexTrojan.GenAsa!CiWfR71FLzs
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.9317601.susgen
FortinetPossibleThreat

How to remove Malware.AI.4084778638?

Malware.AI.4084778638 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment