Malware

About “Malware.AI.4148600076” infection

Malware Removal

The Malware.AI.4148600076 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4148600076 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (16 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Indonesian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rhm-files.blogspot.com
www.bing.com
www.rhm-files.com
www.blogger.com
pagead2.googlesyndication.com
pastebin.com
maxcdn.bootstrapcdn.com
fonts.googleapis.com
ocsp.digicert.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.pki.goog

How to determine Malware.AI.4148600076?


File Info:

crc32: EA7BB13E
md5: 605f08a3963c7da75bc25df9b0945001
name: 605F08A3963C7DA75BC25DF9B0945001.mlw
sha1: eb7e1c0e0401d8c2a43c3865d76892404054d6c2
sha256: dd9f9a676cc6c0df4cc60de3afc5ff72dcb63104665c9d1f16d2c8db953d1dfa
sha512: 38f3e60f28b289dabd69c814beeb813d64a2040d3da1f5f23ff665981763e10c64c6d178f6996efeb87f65c8c4555c3f6cd720f2dabd1df8b33567db270d403e
ssdeep: 49152:Cs81Q0az7JMTWs81Q0az7JMTDMTYNB81Q0ahrLEULzdHFUt:bSM7SSM7GNBSaTXd6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright xa9 Rhm-Files 2017 - All Right Reserved
InternalName: xb5xbfRHMFILESxb3_GTA
FileVersion: 1.00.0096
CompanyName: http://rhm-files.blogspot.com
Comments: Resource Injector Created By Markus Tunggul Wulung Aji
ProductName: Resource Injector
ProductVersion: 1.00.0096
FileDescription: Cheat GTA San Andreas Multiplayer SA-MP
OriginalFilename: xb5xbfRHMFILESxb3_GTA.exe

Malware.AI.4148600076 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.7212
MicroWorld-eScanGen:Trojan.Heur.Ln0@fL1iHpkO
FireEyeGeneric.mg.605f08a3963c7da7
ALYacGen:Trojan.Heur.Ln0@fL1iHpkO
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusUnwanted-Program ( 004b8a411 )
BitDefenderGen:Trojan.Heur.Ln0@fL1iHpkO
K7GWUnwanted-Program ( 004b8a411 )
BitDefenderThetaAI:Packer.CEB35C661C
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
RisingTrojan.Generic@ML.93 (RDML:NqenhJ9Nl3w0N1ckmcZpQQ)
Ad-AwareGen:Trojan.Heur.Ln0@fL1iHpkO
EmsisoftGen:Trojan.Heur.Ln0@fL1iHpkO (B)
F-SecureHeuristic.HEUR/AGEN.1116426
McAfee-GW-EditionBehavesLike.Win32.PUP.tc
SentinelOneStatic AI – Malicious PE
SophosGeneric PUA OL
IkarusPUA.HackTool.Inject
AviraHEUR/AGEN.1116426
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Heur.ED5B3F
GDataGen:Trojan.Heur.Ln0@fL1iHpkO
CynetMalicious (score: 100)
McAfeeArtemis!605F08A3963C
MAXmalware (ai score=84)
MalwarebytesMalware.AI.4148600076
APEXMalicious
ESET-NOD32a variant of Win32/HackTool.Inject.BC potentially unsafe
TencentWin32.Trojan.Heur.Wlpn
YandexTrojan.GenAsa!1tOzSwq8Eh4
FortinetRiskware/Generic_PUA_OL
AVGWin32:Malware-gen
Cybereasonmalicious.3963c7
AvastWin32:Malware-gen

How to remove Malware.AI.4148600076?

Malware.AI.4148600076 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment