Malware

About “Malware.AI.4178581941” infection

Malware Removal

The Malware.AI.4178581941 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4178581941 virus can do?

  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Malware.AI.4178581941?


File Info:

crc32: 971C774D
md5: eea5371f735d01863e8715dc089bffd3
name: EEA5371F735D01863E8715DC089BFFD3.mlw
sha1: 32b126d6cb40c17b3808a66a325336cd855aeb7e
sha256: 0c79f7e4353fb5f0044dbfd5f65dc13cf14c904f491016616b5ef8aacd6654f0
sha512: 5283e0b3fdb81df33bc7ad078c85da4e2fb9e8cb8c04c26a807e616befffc446b2d7767857a3aedea64f06cb524775337847a154de2f04bd2ef802463d5c8a0a
ssdeep: 49152:dhqr+iGQZa2j+nmNUFzSQ3pejUwx6MtojT4Vyz:dIrp/+mKFWQ5ejbtI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright(C) 2020 RecordInfo
InternalName: x8bb0x5f55x6d88x606fx6a21x5757
FileVersion: 2.0.0.1
CompanyName:
LegalTrademarks: RecordInfo
ProductName: x8bb0x5f55x6d88x606fx6a21x5757
ProductVersion: 2.0.0.1
FileDescription: x65b0x529fx80fdx6a21x5757Bx7248
Translation: 0x0804 0x04b0

Malware.AI.4178581941 also known as:

K7AntiVirusAdware ( 00579d641 )
Elasticmalicious (high confidence)
CynetMalicious (score: 85)
ALYacGen:Trojan.Heur.JP.YnLfaypSxakj
CylanceUnsafe
ZillyaAdware.Agent.Win32.163754
SangforTrojan.Win32.Heur.JP
AlibabaAdWare:Win32/Generic.637624a0
K7GWAdware ( 00579d641 )
Cybereasonmalicious.f735d0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Agent.NUZ
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
BitDefenderGen:Trojan.Heur.JP.YnLfaypSxakj
MicroWorld-eScanGen:Trojan.Heur.JP.YnLfaypSxakj
TencentMalware.Win32.Gencirc.11bb9323
Ad-AwareGen:Trojan.Heur.JP.YnLfaypSxakj
SophosGeneric PUA DC (PUA)
BitDefenderThetaAI:Packer.7A0C2F381F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.eea5371f735d0186
EmsisoftGen:Trojan.Heur.JP.YnLfaypSxakj (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftAdware.Softcnapp.sd!c
ArcabitTrojan.Heur.JP.YnLfaypSxakj
GDataGen:Trojan.Heur.JP.YnLfaypSxakj
McAfeeGenericRXAA-AA!EEA5371F735D
MAXmalware (ai score=89)
MalwarebytesMalware.AI.4178581941
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H09CT21
RisingAdware.Agent!1.D0A9 (CLOUD)
YandexPUA.Agent!6t8rdDL+x7s
FortinetRiskware/Agent
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASRsA

How to remove Malware.AI.4178581941?

Malware.AI.4178581941 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment