Malware

What is “Malware.AI.4112638067”?

Malware Removal

The Malware.AI.4112638067 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4112638067 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4112638067?


File Info:

name: DE880274DCD7EC3EBF4E.mlw
path: /opt/CAPEv2/storage/binaries/a3f88dac778d3c59e7157ee9fe6a5133ac89708795caad1c83f98f725e6d800e
crc32: BC31FC04
md5: de880274dcd7ec3ebf4e61e843662be3
sha1: c1ef2ca62189121934d1a7944ef1bdc1aa319877
sha256: a3f88dac778d3c59e7157ee9fe6a5133ac89708795caad1c83f98f725e6d800e
sha512: 574db8d0049d673b0e938bf9acf51f961115feb42a766d686950fbe429231c4a446a7b61b34407d1bc98a2e853805a56a94dd1d17c62acbe41667cc6995ff7f9
ssdeep: 768:FDxO+dUh5OOqulVgD/hB8RcjN6HHmHHSA2SscBjh0TdC6Zu:DOI4cOqegDJB8RaYJijh0dbU
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T11833A20722EC3EE1E0BD5B357B33A3C18378EE155623DA5E1ED4205AA97E203BA517C5
sha3_384: 787b0e827e3fe6117bfcbe1fec10720948d8824e1125772a19045da7b5bc6b76a64537b4028578ff86d1e6bc9e0ee6d8
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-03-12 04:30:49

Version Info:

Translation: 0x0000 0x04b0
FileDescription: MyClientPlugin
FileVersion: 1.0.0.0
InternalName: MyClientPlugin.dll
LegalCopyright: Copyright © 2014
OriginalFilename: MyClientPlugin.dll
ProductName: MyClientPlugin
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4112638067 also known as:

BkavW32.Common.A30D582B
LionicTrojan.Win32.NanoCore.4!c
ElasticWindows.Trojan.Nanocore
MicroWorld-eScanTrojan.GenericKD.3437588
ClamAVWin.Trojan.Nanocore-5
FireEyeTrojan.GenericKD.3437588
SkyhighNanoCore!DE880274DCD7
McAfeeNanoCore!DE880274DCD7
Cylanceunsafe
ZillyaTrojan.NanoCore.Win32.9339
SangforBackdoor.Msil.Nanocore.Vtit
K7AntiVirusTrojan ( 004c74a41 )
K7GWTrojan ( 004c74a41 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/NanoCore.G
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.3437588
NANO-AntivirusTrojan.Win32.Nanocore.ekxlao
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.14003b1e
EmsisoftTrojan.GenericKD.3437588 (B)
F-SecureTrojan.TR/NanoCore.jcui
DrWebTrojan.Nanocore.498
VIPRETrojan.GenericKD.3437588
TrendMicroTROJ_FRS.0NA103GP21
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataMSIL.Backdoor.Nancat.I
WebrootW32.Trojan.Gen
AviraTR/NanoCore.jcui
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Generic.D347414
ViRobotTrojan.Win32.Z.Nanocore.50176
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftBackdoor:MSIL/Noancooe.B
GoogleDetected
AhnLab-V3Backdoor/Win.Noancooe.C5430713
ALYacTrojan.GenericKD.3437588
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.4112638067
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103GP21
YandexTrojan.NanoCore!gdnIyrBLs0Q
IkarusTrojan.MSIL.NanoCore
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Nanocor.GT!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.4112638067?

Malware.AI.4112638067 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment