Malware

Malware.AI.4132271567 removal

Malware Removal

The Malware.AI.4132271567 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4132271567 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior

How to determine Malware.AI.4132271567?


File Info:

name: 72D01C50AC212DE22FA0.mlw
path: /opt/CAPEv2/storage/binaries/8c2fe98c1cb7fb7574540b181774159254f5e775f21f4ce1b499fa54d86b3c6c
crc32: C9CACAD5
md5: 72d01c50ac212de22fa0c231fe5f8aa2
sha1: 94eddf07bb0c37c5ff9676407d4246a5dd6172ba
sha256: 8c2fe98c1cb7fb7574540b181774159254f5e775f21f4ce1b499fa54d86b3c6c
sha512: b94b71c4c6de02fb8429bc6775d14872fa64a37c3753eea47468a2beaf4cce5cdbfaf79572344738f168c556508524e71da6f3451b1b61db13883bd22f7a740e
ssdeep: 6144:RqnNYhnfKrO5syBEQBzlgouHvyv4rpx5T/4DO/B5fpRr3TmiTVVmVVV8VVNVVVcO:Xa5j4DO/B5fn5cO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110842B42CF88108BEC369B31D1F1B7994B37B9D4B9E99FAE21693D2D3C90A409C52375
sha3_384: fa2b6b1809660b2c4a3128eeac51fd9f3f2a18cbda8e2818313626597de5105256acfd2345798a75eb0d0e547d78abad
ep_bytes: 558bec6aff684031400068b022400064
timestamp: 2011-03-15 04:06:07

Version Info:

0: [No Data]

Malware.AI.4132271567 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34110279
FireEyeGeneric.mg.72d01c50ac212de2
CAT-QuickHealW32.Zombie.A4
McAfeeGenericRXNR-SA!72D01C50AC21
CylanceUnsafe
VIPRETrojan.Win32.Cosmu.bwts (v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.34110279
K7GWTrojan ( 0055e3dd1 )
K7AntiVirusTrojan ( 0055e3dd1 )
CyrenW32/Cosmu.H.gen!Eldorado
ESET-NOD32Win32/Agent.NBJ
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Trojan.Cosmu-1058
KasperskyTrojan.Win32.Cosmu.bwts
NANO-AntivirusTrojan.Win32.Cosmu.bgzaxj
RisingTrojan.Zombie!8.2DA5 (RDMK:cmRtazqZA6YRCTDRdADX/kB5jVbL)
Ad-AwareTrojan.GenericKD.34110279
EmsisoftTrojan.GenericKD.34110279 (B)
ComodoTrojWare.Win32.Agent.NBJ@4xjtww
DrWebTrojan.Encoder.185
ZillyaTrojan.Cosmu.Win32.12187
TrendMicroTROJ_SPNR.15CC13
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fm
SophosMal/Behav-112
GDataTrojan.GenericKD.34110279
JiangminTrojan/Cosmu.ppf
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.13CA44
KingsoftHeur.SSC.2787082.0010.(kcloud)
ArcabitTrojan.Generic.D2087B47
MicrosoftTrojan:Win32/Zombie.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cosmu.R51515
BitDefenderThetaGen:NN.ZexaF.34182.yqZ@aGBV9uib
ALYacTrojan.GenericKD.34110279
MAXmalware (ai score=87)
VBA32Trojan.Cosmu
MalwarebytesMalware.AI.4132271567
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.15CC13
TencentVirus.Win32.Cosmu.a
YandexTrojan.GenAsa!qZCC7vZoV+4
MaxSecureTrojan.Cosmu.bwts
FortinetW32/Agent.NBJ!tr
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.0ac212

How to remove Malware.AI.4132271567?

Malware.AI.4132271567 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment