Malware

Should I remove “Malware.AI.4118914244”?

Malware Removal

The Malware.AI.4118914244 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4118914244 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (9 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Behavior consistent with a dropper attempting to download the next stage.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

ip-api.com
www.listincode.com
nixsd.xyz
cor-tips.com
www.facebook.com
ocsp.digicert.com
statuse.digitalcertvalidation.com
iplogger.org
email.yg9.me
iw.gamegame.info
ol.gamegame.info
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
www.bing.com
uehge4g6gh.2ihsfa.com

How to determine Malware.AI.4118914244?


File Info:

crc32: 21E82B99
md5: 796708f87e9e5c7a4e5673725a3e65b9
name: 796708F87E9E5C7A4E5673725A3E65B9.mlw
sha1: afdc6f1a4c49795a9daaadc9f4586e57747d0c1b
sha256: d8a3df5d5ed44873fc091b44a64f98c6c54dae8356d747cddee51b88df9f1d2e
sha512: 702909ddc9c1bffb921a4aeb8b60931b07b46aa51ef2148b629ae586afa11fab17143b22ac604ca7b37d6d99c6e152afb7c158af7450e7a391b2b4f01d8fb645
ssdeep: 98304:UbODpoD2hPzo5q9Pc9aqheNRNoY1tUQrEGIkyZ9rR01gDn:UPDe9Pc9aTHNozljN01gDn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4118914244 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056e5201 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.56088
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak
ALYacTrojan.SmokeLoader
CylanceUnsafe
ZillyaTrojan.ScriptKD.JS.10
SangforTrojan.Win32.Chapak.ezqc
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanDownloader:Win32/CookiesStealer.1c4dc53d
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.87e9e5
CyrenW32/Trojan.KRFM-4077
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Generic-9866235-0
KasperskyTrojan.Win32.Chapak.ezqc
BitDefenderTrojan.GenericKD.37097704
NANO-AntivirusTrojan.Win32.Redcap.iwigjy
MicroWorld-eScanTrojan.GenericKD.37097704
Ad-AwareTrojan.GenericKD.37097704
SophosMal/Generic-S
ComodoMalware@#1y9ldmnlgbx1u
BitDefenderThetaGen:NN.ZemsilF.34738.jm0@aGUiGpb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0PFD21
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeTrojan.GenericKD.37097704
EmsisoftTrojan.GenericKD.37097704 (B)
SentinelOneStatic AI – Malicious SFX
WebrootW32.Trojan.Gen
AviraTR/Dldr.Autoit.vyohg
Antiy-AVLTrojan/Generic.ASMalwS.337C990
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/CookiesStealer.OE!MTB
GridinsoftRansom.Win32.Banker.dd!n
ArcabitTrojan.Generic.D23610E8
AegisLabTrojan.Win32.Chapak.4!c
ZoneAlarmTrojan.Win32.Chapak.ezqc
GDataWin32.Trojan.BSE.BOGPPI
AhnLab-V3Trojan/Win.Generic.R425371
McAfeeArtemis!796708F87E9E
MAXmalware (ai score=100)
VBA32Trojan.Chapak
MalwarebytesMalware.AI.4118914244
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WFF21
RisingTrojan.Kryptik!1.D63F (CLASSIC:72ydvmfMFfjvgPN45hXNRQ)
YandexTrojan.Confuser!p3Ur3lIb2a4
FortinetW32/Autoit.PDT!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.4118914244?

Malware.AI.4118914244 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment