Malware

About “Malware.AI.4096411580” infection

Malware Removal

The Malware.AI.4096411580 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4096411580 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Creates a hidden or system file

How to determine Malware.AI.4096411580?


File Info:

name: D87A41906328B163EBD9.mlw
path: /opt/CAPEv2/storage/binaries/3d17d17c07ec398dcf93facb818abd3a1389b37da508b7963728b523ae7946d3
crc32: 7F00AB41
md5: d87a41906328b163ebd908e158667b9a
sha1: bd47cda5ec679faf6176eee8866a81ae13818641
sha256: 3d17d17c07ec398dcf93facb818abd3a1389b37da508b7963728b523ae7946d3
sha512: 56e44320db0b0a5fa3edd46892acfcd4c10add9aa013d42f30b5b6399bf5a3aa96606112f65b5c716b0c6affa691409d2259ea46db453386b3a8b0bcebddd557
ssdeep: 3072:gj/4Wf4/nptnHDz4wQyindnnsGPuwi3Zy8F/ieEi:gjQWw/zHD09towi3w8F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152C31288F67C7813FBA40B36765A43FA8AE374911792220B065CDBCEDF3314CC950A5A
sha3_384: 341b062b34de33c935b9bc570255ecf9d0d5ae14a58e906aabe4290023720bf3fc5286a5c1105d5adc3546071344b6ed
ep_bytes: 60be00b041008dbe0060feff57eb0b90
timestamp: 2016-05-10 22:18:20

Version Info:

CompanyName: Verify Tool
FileDescription: Verify Tool
FileVersion: 0. 0. 0. 0
InternalName: Verify Tool
LegalCopyright: Verify Tool
LegalTrademarks: Verify Tool
OriginalFilename: Verify.exe
ProductName: Verify Tool
ProductVersion: 0. 0. 0. 0
Comments: Verify Tool
Translation: 0x0409 0x04e4

Malware.AI.4096411580 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d87a41906328b163
McAfeeArtemis!D87A41906328
ZillyaDropper.Agent.Win32.285965
SangforSuspicious.Win32.Attribute.HighConfidence
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanDropper:BAT/Delphi.56543268
K7GWRiskware ( 00584baa1 )
CyrenW32/Delf_Troj.BF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.CoinMiner-9866354-1
NANO-AntivirusTrojan.Win32.Samca.elotdn
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
IkarusTrojan.BAT.Crypt
GDataWin32.Trojan.Agent.5GOJEK
JiangminClient-SMTP.Blat.ag
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1F24EE0
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C2929863
VBA32Trojan.Pynamer
MalwarebytesMalware.AI.4096411580
YandexTrojan.GenAsa!fHFEUiatRPg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.4096411580?

Malware.AI.4096411580 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment