Malware

Malware.AI.4104900558 information

Malware Removal

The Malware.AI.4104900558 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4104900558 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4104900558?


File Info:

name: 1AFF088DEEF0D98155FA.mlw
path: /opt/CAPEv2/storage/binaries/81f719975a571fea26e541dd7c04d979fa5054ae4f70b91fdb4621473a56f839
crc32: F17B2863
md5: 1aff088deef0d98155fac8e88511e28c
sha1: 17cd106a86d0d7262d29b38887e594ac73f0977d
sha256: 81f719975a571fea26e541dd7c04d979fa5054ae4f70b91fdb4621473a56f839
sha512: 3038a5a8e000d55cfaf3a33d5f27a7a3330ffaba24a7d6d0931f93e922bd8021877901beda544aeb2bae0bc3f39e7e7c6fc7275db5abd880d0aa812f3e8fa9a3
ssdeep: 24576:tTOHJ529+RipvL1SXk1QE1RGOTnIEQc4au9NgxnHNn+1h8kNG3:tX9+ApwXk1QE1RzsEQPaxHN+1qUG3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B750113B6E18432D0633234AAAFC76AA6253C3997E1A53F67AC2F0F8D74141B716771
sha3_384: 8bf3877d01478bc8bddc8ea7c6a9ed336869c99e08f95a41c5caa36f2d245c5330f90d2b08441394c1ba77047eeb5ee2
ep_bytes: e8214a0000e97ffeffff558bec8b4508
timestamp: 2018-03-15 17:54:32

Version Info:

Comments: http://www.autoitscript.com/autoit3/
CompanyName: AutoIt Team
FileDescription: Aut2Exe
FileVersion: 3, 3, 14, 5
InternalName: Aut2Exe.exe
LegalCopyright: ©1999-2018 Jonathan Bennett & AutoIt Team
OriginalFilename: Aut2Exe.exe
ProductName: Aut2Exe
ProductVersion: 3, 3, 14, 5
Translation: 0x0809 0x04b0

Malware.AI.4104900558 also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
MicroWorld-eScanGen:Variant.Zusy.487498
FireEyeGen:Variant.Zusy.487498
ALYacGen:Variant.Zusy.487498
MalwarebytesMalware.AI.4104900558
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Kryptik.BOK.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
BitDefenderGen:Variant.Zusy.487498
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.13f05bb3
EmsisoftGen:Variant.Zusy.487498 (B)
DrWebWin32.Beetle.2
VIPREGen:Variant.Zusy.487498
McAfee-GW-EditionBehavesLike.Win32.Mabezat.tc
Trapminemalicious.moderate.ml.score
IkarusVirus.Win64.Expiro
GDataGen:Variant.Zusy.487498
Antiy-AVLTrojan/Win32.Patched
ArcabitTrojan.Zusy.D7704A
ZoneAlarmHEUR:Backdoor.Win32.Convagent.gen
MicrosoftTrojan:Win32/Doina.RPX!MTB
GoogleDetected
AhnLab-V3Malware/Win.Generic.R603893
MAXmalware (ai score=82)
VBA32BScope.Trojan.Meterpreter
RisingTrojan.Generic@AI.100 (RDML:V+FhtwchqWRUznGQPijrOw)
FortinetW32/Patched.IP!tr
BitDefenderThetaGen:NN.ZexaF.36738.Gr0@a4eQIXai
Cybereasonmalicious.a86d0d

How to remove Malware.AI.4104900558?

Malware.AI.4104900558 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment