Malware

Should I remove “Malware.AI.4118078011”?

Malware Removal

The Malware.AI.4118078011 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4118078011 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4118078011?


File Info:

name: 61AE3E83438E2FFB4DDA.mlw
path: /opt/CAPEv2/storage/binaries/14d16b47a79083121d00179486bbab76f8c9b4e55b29f47145f15f66134a9914
crc32: ACE03838
md5: 61ae3e83438e2ffb4dda8fc1cd08b7ed
sha1: 3d2468d11a193fa60d9c5fc74817e88efcdc69b0
sha256: 14d16b47a79083121d00179486bbab76f8c9b4e55b29f47145f15f66134a9914
sha512: a5a88f8f949d10a639223a31b8e3fd0cf4ba46d1c89d5f15769d80a894ce6da6d07520f6783aae868a2c8b95774aec76c67e5f87609f0a99aabf6b1932a94e30
ssdeep: 49152:Ruc+FPwVTk+lQh97ReMYSZhL6j1KWSi6PIEHvuhn3MVwi0A/fr:wRwVTk+e9deMY+Z6CPIEPuV3a/T
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1599523F1A2902ECAF906C2B00F6EC7D1FBF3C6F46C351878550B676654B1A60F9E065A
sha3_384: 9d081897704d53105b8bc147f3aa6e95aff5988b75ec7eca513452f369693380510fad23536af7529dfcfeb6851ac931
ep_bytes: 60be2225d2ed21c929f129f161f7d129
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.4118078011 also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.576052
FireEyeGeneric.mg.61ae3e83438e2ffb
ALYacGen:Variant.Razy.576052
Cylanceunsafe
ZillyaTrojan.Injector.Win32.1636466
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057fe481 )
AlibabaTrojan:Win32/Injector.eb12d89a
K7GWTrojan ( 0057fe481 )
Cybereasonmalicious.3438e2
BitDefenderThetaGen:NN.ZexaF.36250.0nZ@aGXXzDe
CyrenW32/Injector.AJF.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ECAV
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.576052
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Tiggre.ka
SophosMal/Generic-S
VIPREGen:Variant.Razy.576052
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
EmsisoftGen:Variant.Razy.576052 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.576052
Antiy-AVLTrojan/Win32.Injector
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Razy.D8CA34
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R554362
Acronissuspicious
McAfeeGenericRXAA-FA!61AE3E83438E
MAXmalware (ai score=81)
VBA32Trojan.Copak
MalwarebytesMalware.AI.4118078011
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Xed-10
RisingTrojan.Injector!1.C865 (CLASSIC)
IkarusTrojan.Win32.Injector
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4118078011?

Malware.AI.4118078011 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment