Malware

Malware.AI.4179819278 malicious file

Malware Removal

The Malware.AI.4179819278 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4179819278 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4179819278?


File Info:

name: E95F57D1832C552FA0CC.mlw
path: /opt/CAPEv2/storage/binaries/d943ede258513f4194f7e033556a71ebda6bbb38980b2d7061a454183cd77a6e
crc32: 51613856
md5: e95f57d1832c552fa0cc8f312cb5f81e
sha1: 0436d15b4d78fc79c069f417042657a75483332c
sha256: d943ede258513f4194f7e033556a71ebda6bbb38980b2d7061a454183cd77a6e
sha512: b5fd4aaa1c5d3913ef17f0e970aa60814d1c6d50d515f370164858c0b709b1693d8f43b53e004bd9eff908935abe12697a6d11fd54f9096348f3f7089acc450d
ssdeep: 12288:RYPVeKjKeDN9OW7IC/xYcDrQWwcW1K3DnsTen:RYPflDT5IC/+cDrQWRW4DsTY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1378423A0B267ED27D0C1923968F1955B88D7AE070C85C7138BA9740155FE3CDAA0E7FB
sha3_384: 2817e05688d72a0db99381b2c5b568c3d48dced2bc99b8a92378c0c63d220d9e4b92b59c3df02a13ab68584026b2b19b
ep_bytes: 6801205900e801000000c3c3118a493f
timestamp: 1988-06-30 17:51:41

Version Info:

0: [No Data]

Malware.AI.4179819278 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Genome.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.15592
FireEyeGeneric.mg.e95f57d1832c552f
ALYacGen:Variant.Symmi.15592
ZillyaTrojan.Genome.Win32.192385
AlibabaTrojanSpy:Win32/Genome.10be3802
Cybereasonmalicious.1832c5
BitDefenderThetaGen:NN.ZexaF.36196.yCWaaOv9Iuf
CyrenW32/Zbot.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.15592
NANO-AntivirusTrojan.Win32.TrjGen.bksdfx
AvastWin32:Evo-gen [Trj]
TACHYONTrojan/W32.Genome.397824.F
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.Click2.36980
VIPREGen:Variant.Symmi.15592
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.15592 (B)
GDataGen:Variant.Symmi.15592
JiangminTrojan/Genome.cita
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Win32.Genome
XcitiumMalware@#1bxracn8sccl8
ArcabitTrojan.Symmi.D3CE8
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot.gen!AJ
GoogleDetected
AhnLab-V3Trojan/Win32.Genome.R38280
McAfeePWS-Zbot.gen.anz
VBA32Trojan.Genome.ag
MalwarebytesMalware.AI.4179819278
PandaTrj/Zbot.M
RisingSpyware.Zbot!8.16B (TFE:5:wAKbGTiXFqH)
YandexTrojan.GenAsa!tLbD6YjaCLM
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.5151839.susgen
FortinetW32/Zbot.AAO!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.4179819278?

Malware.AI.4179819278 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment