Malware

Malware.AI.4137786964 removal tips

Malware Removal

The Malware.AI.4137786964 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4137786964 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Arabic (Algeria)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.4137786964?


File Info:

crc32: 50C88148
md5: c5894590516cfafbbc2a49421b33c24a
name: C5894590516CFAFBBC2A49421B33C24A.mlw
sha1: 526436e78a44bce61296ccb1d508caf89a380e66
sha256: 05e8482dc94518f4161275e98e0acb514ca09963fe1527f126aa167e38f96897
sha512: 48e67d59cbe9e3ba37c12317b7e9321bfcb4c4e2abbee7e636e447938961aa6c3728eab6354c9eb56a33b3c564ad680c8837e76c1fbe68ec8fbb9f9384f6333d
ssdeep: 6144:ebEyiiSRU6LTnBzW81tMyr2IIfzp0yN90vE:e7i5Rnj+E2My90
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: x202dxa9 Microsoft Corporation. All rights reserved.x202c
InternalName: Wextract
FileVersion: 8.00.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Windowsxae Internet Explorer
ProductVersion: 8.00.7600.16385
FileDescription: x200ex200ex627x644x627x633x62ax62ex631x627x62c x627x644x630x627x62ax64a x644x645x644x641 x62ex632x627x646x629 Win32
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0401 0x04b0

Malware.AI.4137786964 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e39a1 )
LionicTrojan.MSIL.Agent.i!c
DrWebBackDoor.Bifrost.19762
CynetMalicious (score: 99)
ALYacTrojan.Generic.6830654
CylanceUnsafe
SangforTrojan.Win32.Wacatac.C
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:MSIL/Injector.b92cc434
K7GWTrojan ( 0055e39a1 )
Cybereasonmalicious.0516cf
CyrenW32/SysVenFak.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.HE
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.6830654
NANO-AntivirusTrojan.Win32.Bifrost.csfhkt
MicroWorld-eScanTrojan.Generic.6830654
TencentMsil.Trojan-qqpass.Qqrob.Syht
Ad-AwareTrojan.Generic.6830654
SophosMal/Generic-S
ComodoMalware@#16kx065re071s
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
FireEyeGeneric.mg.c5894590516cfafb
EmsisoftTrojan.Generic.6830654 (B)
JiangminTrojan/Generic.aagwo
AviraHEUR/AGEN.1120740
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA05
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
GDataTrojan.Generic.6830654
Acronissuspicious
McAfeeArtemis!C5894590516C
MAXmalware (ai score=89)
VBA32Trojan.KillProc
MalwarebytesMalware.AI.4137786964
PandaTrj/CI.A
YandexTrojan.Agent!sr/NR0Y67RM
IkarusTrojan.Win32.Genome
FortinetW32/Generic.AC.32B4!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Malware.AI.4137786964?

Malware.AI.4137786964 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment