Malware

Should I remove “Malware.AI.4162987964”?

Malware Removal

The Malware.AI.4162987964 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4162987964 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io

How to determine Malware.AI.4162987964?


File Info:

crc32: BFF1CD2E
md5: b6b1eb0d7ac7d3a9d99783afb84f5fc4
name: B6B1EB0D7AC7D3A9D99783AFB84F5FC4.mlw
sha1: 55df2808e0d76f015971e230849c6ce8451accc8
sha256: 991de3dc457f69cc933cec06fd2a151b355cd166b2c6228c7e13ae3829f72edd
sha512: 05c8322d2a356ac8851647d500f5859abb1881bca0cbbf7fd5be4284ea8055df73e97c395fd3783c57eea52d40cff142ebe4e72a90a029c758bbe17816455965
ssdeep: 6144:rwppYYwpthZupEHBFRqZy7KbX26kaJ0y1:rSYYQthEpwAC21
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2008-2011 x41ex41ex41e x42fx43dx434x435x43ax441
InternalName: Punto Switcher Unloader
FileVersion: 3.2.3.51
CompanyName: x41e x41ex41e x42fx43dx434x435x43ax441
LegalTrademarks: Punto Switcher
Comments: x412x44bx433x440x443x437x447x438x43a Punto Switcher
ProductName: Punto Switcher
ProductVersion: 3.2.3.51
FileDescription: x412x44bx433x440x443x437x447x438x43a Punto Switcher
OriginalFilename: puntounloader.exe
Translation: 0x0419 0x04b0

Malware.AI.4162987964 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
CAT-QuickHealRansom.Cerber.G4
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a (v)
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 005224381 )
Cybereasonmalicious.d7ac7d
BaiduWin32.Trojan.Kryptik.awu
CyrenW32/S-b9788ac3!Eldorado
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-6931819-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.b83121b9
NANO-AntivirusTrojan.Win32.Encoder.evdbfq
RisingTrojan.Kryptik!1.AF0E (CLOUD)
Ad-AwareTrojan.Ransom.Cerber.1
EmsisoftTrojan.Ransom.Cerber.1 (B)
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
F-SecureHeuristic.HEUR/AGEN.1129194
DrWebTrojan.Encoder.4939
ZillyaTrojan.Zerber.Win32.252
TrendMicroRansom_CERBER.SMEJ5
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.b6b1eb0d7ac7d3a9
SophosML/PE-A + Mal/Ransom-EJ
IkarusTrojan.Crypt
JiangminTrojan.Zerber.od
AviraHEUR/AGEN.1129194
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Ransom.Cerber.1
SUPERAntiSpywareRansom.Cerber/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Lukitus2.Exp
Acronissuspicious
McAfeeGenericRXAJ-EE!B6B1EB0D7AC7
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.4162987964
PandaTrj/Genetic.gen
ESET-NOD32Win32/Filecoder.Cerber.B
TrendMicro-HouseCallRansom_CERBER.SMEJ5
TencentMalware.Win32.Gencirc.10b55b29
YandexTrojan.GenAsa!+JPqBQ6yYzA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Dridex.IZC!tr
BitDefenderThetaGen:NN.ZexaF.34590.mq0@a0ozZggk
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.Cerber.HxQBfRYA

How to remove Malware.AI.4162987964?

Malware.AI.4162987964 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment