Malware

About “Malware.AI.4141022115” infection

Malware Removal

The Malware.AI.4141022115 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4141022115 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4141022115?


File Info:

name: BF31331B5B600AAD640E.mlw
path: /opt/CAPEv2/storage/binaries/696b6724df0fa570c06b0d7a3ae487a8791e95d7c04ead4c5feca130d80fc15a
crc32: 8203FD59
md5: bf31331b5b600aad640eb30eba0634da
sha1: 8e8d514d878a45ec38954e21ed37993dd7c36f51
sha256: 696b6724df0fa570c06b0d7a3ae487a8791e95d7c04ead4c5feca130d80fc15a
sha512: 1293a87c08605d16aee69f75abf6a1185b3c70105077d764cd9232aa013f8da792f1aa42380ff919372dc97f8132b78c0ea28aae101cea6704a13e98d12dd6ad
ssdeep: 49152:cYgwRxXQm5JIDyFKurdJvkPsuyMyx0q4PSAJFJ2eIjGjiXPtyem3d:cYgwDXQSJIDyFKkGywKAJz2FYeC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104B53340B3CEE1B9EC79557CCC4ABACCC1F625642B9A959F1E0D4C526AF8F92870E407
sha3_384: 4e576e940173e819e95ea8ae803a03b16301127d0e71ab1e4f47a012d6043615c821888a12bf18406bc4ba6613cd80c2
ep_bytes: 558bec6aff688083400068907e400064
timestamp: 2016-10-04 15:13:34

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX small
FileVersion: 16.04
InternalName: 7zS2.sfx
LegalCopyright: Igor Pavlov : Public domain
OriginalFilename: 7zS2.sfx.exe
ProductName: 7-Zip
ProductVersion: 16.04
Translation: 0x0409 0x04b0

Malware.AI.4141022115 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.520487
ClamAVWin.Packed.Zenpak-10014145-0
FireEyeGen:Variant.Zusy.520487
SkyhighArtemis
McAfeeArtemis!BF31331B5B60
MalwarebytesMalware.AI.4141022115
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/grayware_confidence_60% (D)
ArcabitTrojan.Zusy.D7F3AB
BitDefenderThetaGen:NN.ZedlaF.36792.zw8@aqP2duni
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HVHE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Fero.ff
BitDefenderGen:Variant.Zusy.520487
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:DropperX-gen [Drp]
F-SecureTrojan.TR/AD.Fauppod.jcaqx
ZillyaTrojan.Zenpak.Win32.20274
EmsisoftGen:Variant.Zusy.520487 (B)
IkarusTrojan.Win32.Krypt
JiangminRemoteAdmin.NetCat.es
GoogleDetected
AviraTR/AD.Fauppod.jcaqx
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmTrojan-Downloader.Win32.Fero.ff
GDataWin32.Trojan.PSE.2LGSSE
VaristW32/Kryptik.LBR.gen!Eldorado
AhnLab-V3Trojan/Win.Zusy.C5466244
VBA32BScope.Trojan.Startun
ALYacGen:Variant.Cerbu.194069
MAXmalware (ai score=84)
RisingDownloader.Fero!8.18DAE (TFE:1:WqJW9q8JkaO)
SentinelOneStatic AI – Malicious SFX
FortinetW32/Kryptik.HUEI!tr
AVGWin32:DropperX-gen [Drp]

How to remove Malware.AI.4141022115?

Malware.AI.4141022115 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment