Malware

Malware.AI.4088176614 removal guide

Malware Removal

The Malware.AI.4088176614 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4088176614 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Network activity contains more than one unique useragent.
  • The following process appear to have been packed with Themida: 6276006398f2a_733005f.exe
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments

How to determine Malware.AI.4088176614?


File Info:

name: 8F4F4415A5DC148C6E8D.mlw
path: /opt/CAPEv2/storage/binaries/7e0a5edb0a8db8fd0fdc075f03e969c7f0422973ea848ae48e4521639d2d75ad
crc32: 9364C303
md5: 8f4f4415a5dc148c6e8dc1e27708c5eb
sha1: e16ff859c245339e2216ad5808fd4787ac19da08
sha256: 7e0a5edb0a8db8fd0fdc075f03e969c7f0422973ea848ae48e4521639d2d75ad
sha512: 2b23a6c4013abb3dac7482f54e98fccedf6baca16f2e5e8b28ef35d57c13732236b930c98b3b64d9d27eda738e6d302acffe72ae0fff38fed0ee6fa35286915f
ssdeep: 196608:JY4hWV9SkB+v/ESsXKIYAgLNbCpSkv6S3tkFihDM9OtlfRNMlhJh6N:JOfBc/ESCsAikvLYihD3tlDihn2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1049633C27D4E517DD7EAA773E548CF808C3F49501422A91F22C65FF55EAB0AAD22342E
sha3_384: 95cc26e6b718f668792f0243ba2bb537084c0969a1618498082dd11b2b61a702bdf5a3e38330ca764b161fc2688c9b15
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:44:18

Version Info:

0: [No Data]

Malware.AI.4088176614 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.45861
CAT-QuickHealBackdoor.Manuscrypt
BitDefenderGen:Variant.Jaik.45861
Cybereasonmalicious.5a5dc1
CyrenW32/MSIL_Kryptik.FLY.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.Pswtool-9857487-0
KasperskyTrojan.Win32.Fsysna.ieps
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ComodoMalware@#2w33on5gyn22j
F-SecureTrojan.TR/Dropper.Gen8
DrWebTrojan.Siggen17.47742
TrendMicroTROJ_GEN.R002C0PDQ22
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.8f4f4415a5dc148c
EmsisoftGen:Variant.Jaik.45861 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Jaik.45861
AviraHEUR/AGEN.1210138
KingsoftWin32.Troj.Agentb.kr.(kcloud)
ArcabitTrojan.Jaik.DB325
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34638.tu0@aiKicsn
ALYacGen:Variant.Jaik.45861
MAXmalware (ai score=80)
MalwarebytesMalware.AI.4088176614
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCEGZ
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:cmRtazo26Vw+b8oXB5DrhKEr2QFC)
IkarusTrojan-Spy.MSIL.Agent
FortinetMSIL/Agent.LCG!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Malware.AI.4088176614?

Malware.AI.4088176614 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment