Malware

About “Malware.AI.4161193713” infection

Malware Removal

The Malware.AI.4161193713 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4161193713 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Malware.AI.4161193713?


File Info:

name: FF3FEBBFB1D9A97CAD94.mlw
path: /opt/CAPEv2/storage/binaries/513d3d85dd8d051ec34371fb95c38e13d6d3bc604344da16c230de62a4d407ed
crc32: 3A17E6D7
md5: ff3febbfb1d9a97cad945ee43737cc0e
sha1: 0b6ae08b1054678dd0bf24e610358485e9867761
sha256: 513d3d85dd8d051ec34371fb95c38e13d6d3bc604344da16c230de62a4d407ed
sha512: 3565cb7bcbb2c6213aff29b87e533c32824ab31dc0fe04f2f138d6cb3b75620eaac28aa939780597ad8cb19b9c52a5615f4d6e5eb464036d6555f600c8a7e1ea
ssdeep: 6144:h98vaUNARKdww07LLqZA46PQEdGfmPaB7/WIvnksEVA14hYp9iY:0xNAC6aZuPDdbPGr1vklodj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F54F164F389C429D138227FAFB88B84C494D2024890DAB8B5D62E167177B7B67B5F43
sha3_384: 4dd9ecd0b67bd92b153f773ada68678664387e9822a69ac88752253972d07c317dbd67d13f3a153f676c855341166d6f
ep_bytes: 68c83c4400e8eeffffff000000000000
timestamp: 2014-01-23 15:50:43

Version Info:

Translation: 0x0404 0x04b0
Comments: Abbiocco Pomeridiano
CompanyName: RoseCitySoftware
ProductName: Araberhäuptlingen5
FileVersion: 2.05.0004
ProductVersion: 2.05.0004
InternalName: ggggggggggg
OriginalFilename: ggggggggggg.exe

Malware.AI.4161193713 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
ClamAVWin.Trojan.Ponystealer-7366807-0
FireEyeGeneric.mg.ff3febbfb1d9a97c
CAT-QuickHealVirTool.VBInject.LE3
McAfeePWSZbot-FLW!FF3FEBBFB1D9
CylanceUnsafe
VIPREGen:Heur.PonyStealer.sm1@du02eGnb
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0040f7be1 )
BitDefenderGen:Heur.PonyStealer.sm1@du02eGnb
K7GWTrojan ( 004e37981 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.PonyStealer.E7D3C8
BitDefenderThetaGen:NN.ZevbaF.34646.sm1@au02eGnb
VirITTrojan.Win32.Generic.BKPQ
CyrenW32/VBInject.EX.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Injector.AWUQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.hiio
NANO-AntivirusTrojan.Win32.Inject.dwyzvv
MicroWorld-eScanGen:Heur.PonyStealer.sm1@du02eGnb
RisingTrojan.PonyStealer!8.112D3 (TFE:3:KX6ZaaqwAxH)
Ad-AwareGen:Heur.PonyStealer.sm1@du02eGnb
TACHYONTrojan/W32.VB-Inject.305159.E
SophosML/PE-A + Troj/VBInj-MJ
ComodoTrojWare.Win32.Injector.AUQV@57ftkq
BaiduWin32.Trojan.Inject.l
ZillyaTrojan.Inject.Win32.67614
TrendMicroTSPY_ZBOT.SMSP
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.PonyStealer.sm1@du02eGnb (B)
IkarusVirus.Win32.Vbcrypt
JiangminTrojan/Inject.aqzu
AviraTR/VB.Injector.zwzd
Antiy-AVLTrojan/Generic.ASMalwS.77
MicrosoftTrojan:Win32/PonyStealer.VB!MTB
SUPERAntiSpywareTrojan.Agent/Gen-FalInt
GDataGen:Heur.PonyStealer.sm1@du02eGnb
GoogleDetected
AhnLab-V3Spyware/Win32.Zbot.R97155
Acronissuspicious
VBA32Trojan.Inject
ALYacGen:Heur.PonyStealer.sm1@du02eGnb
MAXmalware (ai score=86)
MalwarebytesMalware.AI.4161193713
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SMSP
TencentTrojan.Win32.Inject.hiioa
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.AVMN!tr
AVGWin32:Zbot-SNU [Trj]
Cybereasonmalicious.fb1d9a
AvastWin32:Zbot-SNU [Trj]

How to remove Malware.AI.4161193713?

Malware.AI.4161193713 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment