Malware

Malware.AI.4121113945 removal tips

Malware Removal

The Malware.AI.4121113945 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4121113945 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup

How to determine Malware.AI.4121113945?


File Info:

name: 2C1A1C54C77811A32BAC.mlw
path: /opt/CAPEv2/storage/binaries/81f1cc4ccdd4f02bfe5461b53c887fc07385bbf66e2bc1e47cfedbf280acd4b2
crc32: 68B54910
md5: 2c1a1c54c77811a32bac7d701b7f267b
sha1: 6c8bde29039c5d74b6ea9502afe75739cdff0ceb
sha256: 81f1cc4ccdd4f02bfe5461b53c887fc07385bbf66e2bc1e47cfedbf280acd4b2
sha512: b0f9ae52bb02c94c7a6c59d0ad2dd578038a538cbea7348fbe82174f9b19e6677d5fa2d9ebb5f6e495c6bc7cb5c6aecd5ae715387508414e7d39d4c5cbe37cca
ssdeep: 1536:OGvCcwfl2CRTKlWoSRiHL7B7nvyvjcJZvTysWjcd6Zx1XVf4CFuIf:OG6d2CROWoWiHYv4Zvx6ZPXVg3If
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14DA37C02F6D2C471E0B702368C659F614B7EFE779BB589877388164D1A782D04A36BB3
sha3_384: da7565c2dad11efad4873ec6bdb360f6fc0046ff0cd0f2e3cd05919c81d23fa1e15453083afd381d44426dc5904a80ff
ep_bytes: e8de3f0000e9000000006a1468206a41
timestamp: 2014-01-06 04:56:51

Version Info:

0: [No Data]

Malware.AI.4121113945 also known as:

LionicTrojan.Win32.Windef.c!c
MicroWorld-eScanGen:Trojan.ProcessHijack.guW@amaI8chO
FireEyeGeneric.mg.2c1a1c54c77811a3
McAfeeGenericRXAA-AA!2C1A1C54C778
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Injector.DDC
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojan:Win32/Windef.bc73e369
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.4c7781
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DDC
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-FakeAV.Win32.Windef.vtl
BitDefenderGen:Trojan.ProcessHijack.guW@amaI8chO
NANO-AntivirusTrojan.Win32.FakeAV.cteohi
RisingBackdoor.Fynloski!8.1FD (CLOUD)
Ad-AwareGen:Trojan.ProcessHijack.guW@amaI8chO
EmsisoftGen:Trojan.ProcessHijack.guW@amaI8chO (B)
ComodoMalware@#3jps6kmhe4m29
DrWebTrojan.Packed.25354
ZillyaTrojan.Windef.Win32.2720
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
Paloaltogeneric.ml
GDataGen:Trojan.ProcessHijack.guW@amaI8chO
Antiy-AVLTrojan/Generic.ASMalwS.7105F0
GridinsoftRansom.Win32.Skeeyah.sa
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.975588CE1F
ALYacGen:Trojan.ProcessHijack.guW@amaI8chO
MAXmalware (ai score=84)
VBA32TrojanFakeAV.Windef
MalwarebytesMalware.AI.4121113945
TrendMicro-HouseCallTROJ_GEN.R002H0CB822
TencentMalware.Win32.Gencirc.10bb1bfe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GXZM!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4121113945?

Malware.AI.4121113945 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment