Malware

Malware.AI.4097679795 removal instruction

Malware Removal

The Malware.AI.4097679795 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4097679795 virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4097679795?


File Info:

name: 52E6A864E382EB681DC2.mlw
path: /opt/CAPEv2/storage/binaries/f47db0a662556aa5f43179f5b6d0352eac44795e2c278751b150116cb169d8b0
crc32: EA9DB19F
md5: 52e6a864e382eb681dc213394b8b52f1
sha1: 14f7dfb724e69c62278f5142150a68f97794087b
sha256: f47db0a662556aa5f43179f5b6d0352eac44795e2c278751b150116cb169d8b0
sha512: 9a6bb9db19cfdafd09a856a1ee48280b38b53f55123f652bf5b729c52509f1e2d055b03b68477cbc2e8300d8ff8312c6e0630f88197bc8856f239dc7f076e10b
ssdeep: 49152:ISM02szVX3UEMmTQClAeR9U1gFAKFB2eyo7Y:IK2sVnUEZxlAe3B2e5Y
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T140D56B12BCE614B6C5BEE230CA6192627A317C6947313BD72F84A57A1A76FD43E3D301
sha3_384: f8b8cc94be75aa3e4f532b5efbde9e05526fe7fb512aad4f63a112d4a82c8a7bd6a20e2c9dd00149b019bd6d8e929e19
ep_bytes: e97bc8ffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.4097679795 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.38135326
FireEyeTrojan.GenericKD.38135326
ALYacTrojan.GenericKD.38135326
CylanceUnsafe
AlibabaTrojan:Win32/Rozena.e499c4d9
ESET-NOD32a variant of WinGo/Rozena.EO
TrendMicro-HouseCallTROJ_GEN.R002H0CKT21
BitDefenderTrojan.GenericKD.38135326
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.38135326
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win64.Trojan.vh
EmsisoftTrojan.GenericKD.38135326 (B)
APEXMalicious
GDataWin64.Trojan.Agent.KHBJHZ
MAXmalware (ai score=87)
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D245E61E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!52E6A864E382
MalwarebytesMalware.AI.4097679795
IkarusTrojan-Ransom.Hive
RisingTrojan.ShellCode!1.D2D8 (CLASSIC)
FortinetW64/Rozena.AY!tr
AVGWin64:Trojan-gen

How to remove Malware.AI.4097679795?

Malware.AI.4097679795 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment