Categories: Malware

What is “Malware.AI.4130311862”?

The Malware.AI.4130311862 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4130311862 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4130311862?


File Info:

crc32: C808F0EFmd5: b87d5f87c66c30b30b11b4c4c0f8e87bname: B87D5F87C66C30B30B11B4C4C0F8E87B.mlwsha1: 8525481585fb5b29a801d8537c1459a256746ecfsha256: 6269e46d5e6522721a444ae786d58dd0e358f99b73ea82fe500dbce25ee355absha512: 9510ccbf9c29bdc0b3cd7e6953a4dec0eb752b395ed7b7b4d4661ba7d02393af76c7fffbe843ca9a847ccb9af1a248273594c0f344f88ef1695d8107a1198ae1ssdeep: 6144:awTvre+9xzp5AD9SRVAnf/XvHPnnfnHnPn/nnnPn3nfn3nvnHn/nnvH3HvPnXnvM:jTTe+7pO9SRm+type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2012InternalName: servertoolFileVersion: 7.0.40.20Full Version: 1.7.0_04-b20CompanyName: Oracle CorporationProductName: Java(TM) Platform SE 7 U4ProductVersion: 7.0.40.20FileDescription: Java(TM) Platform SE binaryOriginalFilename: servertool.exeTranslation: 0x0000 0x04b0

Malware.AI.4130311862 also known as:

Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Ransom.Cerber.1
FireEye Generic.mg.b87d5f87c66c30b3
CAT-QuickHeal TrojanRansom.Crowti.MUE.A4
Qihoo-360 Win32/Ransom.Cerber.HxQBM1QA
ALYac Trojan.Ransom.Cerber.1
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.Ransom.Cerber.1
K7GW Trojan ( 005224381 )
K7AntiVirus Trojan ( 005224381 )
Baidu Win32.Trojan.Kryptik.avk
Symantec Packed.Generic.459
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Ransomware.Cerber-9816006-0
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Ransom:Win32/Cerber.417a7d4c
NANO-Antivirus Trojan.Win32.Kryptik.evrhwm
Rising Trojan.Kryptik!1.AF0E (CLOUD)
Ad-Aware Trojan.Ransom.Cerber.1
Emsisoft Trojan.Ransom.Cerber.1 (B)
Comodo TrojWare.Win32.Kryptik.FFQQ@6kenxz
F-Secure Trojan.TR/Crypt.ZPACK.Gen
DrWeb Trojan.Encoder.4691
Zillya Trojan.Cerber.Win32.527
TrendMicro Ransom_HPCERBER.SM3
McAfee-GW-Edition Ransomware-FQF!B87D5F87C66C
Sophos Mal/Generic-R + Mal/Cerber-K
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.Generic.brkhs
Avira TR/Crypt.ZPACK.Gen
MAX malware (ai score=100)
Antiy-AVL Trojan/Win32.AGeneric
Microsoft Ransom:Win32/Cerber.A
Arcabit Trojan.Ransom.Cerber.1
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Trojan.Ransom.Cerber.1
Cynet Malicious (score: 100)
Acronis suspicious
McAfee Ransomware-FQF!B87D5F87C66C
VBA32 BScope.Trojan.Encoder
Malwarebytes Malware.AI.4130311862
Panda Trj/GdSda.A
ESET-NOD32 a variant of Win32/Kryptik.FFSE
TrendMicro-HouseCall Ransom_HPCERBER.SM3
Tencent Win32.Trojan.Cerber3.Pgcz
Yandex Trojan.Agent!Btw7yA0xL3I
Ikarus Trojan.Win32.Crypt
eGambit Unsafe.AI_Score_70%
Fortinet W32/Kryptik.HEKH!tr
BitDefenderTheta Gen:NN.ZexaF.34590.oq1@aqiBcMai
AVG Win32:Malware-gen
Paloalto generic.ml

How to remove Malware.AI.4130311862?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.4222225806 malicious file

The Malware.AI.4222225806 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.1862100968 removal guide

The Malware.AI.1862100968 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32:VB-OLS [Trj] removal

The Win32:VB-OLS [Trj] is considered dangerous by lots of security experts. When this infection is…

2 hours ago

How to remove “Trojan:Win32/Smokeloader.CCDO!MTB”?

The Trojan:Win32/Smokeloader.CCDO!MTB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “TrojanDownloader:MSIL/RedLineStealer.KL!MTB”?

The TrojanDownloader:MSIL/RedLineStealer.KL!MTB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

How to remove “Malware.AI.4139232050”?

The Malware.AI.4139232050 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago