Malware

Should I remove “Malware.AI.4180628677”?

Malware Removal

The Malware.AI.4180628677 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4180628677 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • CAPE detected the embedded win api malware family
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.4180628677?


File Info:

name: 056965ECE9C0501436FF.mlw
path: /opt/CAPEv2/storage/binaries/3cfaec9816b425a37765f21e0dbdc3c343ac2b67fe7d2d9664d0ea87fdbefef9
crc32: 5D2F7ED6
md5: 056965ece9c0501436ff5b227132dc27
sha1: bb126ccd3fc8e40793c20fb1988916a501b2140e
sha256: 3cfaec9816b425a37765f21e0dbdc3c343ac2b67fe7d2d9664d0ea87fdbefef9
sha512: 5b3e9eb97e703969da6ffac2d97f812ece3d89bc3b5f70f6c32a1559188af13b849bb41d6b65c255fd2976cd4c759750199f1b9a9ede706137e2c58c80945f71
ssdeep: 12288:5Zf1oOge9keDbIVmEaoLkMKwC0mtRAPO6aBIvVF0RQmSgirtw:XKOYIUkE4A2vINFjUZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132E40230F641903AE5B347B045B9CBF9B124BF30576853CBA3DCA6AA67792C54D3270A
sha3_384: 5e54253c153907c374e1bc2a1145e8958a0e360b30ad3b4a8219cc5fcfba47dd7d03a23a330a233c6716b43e930076e5
ep_bytes: 558bec6aff6890eb480068ac54400064
timestamp: 2007-10-15 04:34:42

Version Info:

CompanyName: Chayorer Exit
FileDescription: Hagare mopis ala whef thage
FileVersion: 1, 2, 1, 1
InternalName: Shared
LegalCopyright: Copyright (C) Ditetes That Montoth 2009. All rights reserved.
OriginalFilename: Shared.exe
ProductName: Envelope distance setting viewing
ProductVersion: 1, 2, 1, 1
Translation: 0x0409 0x04b0

Malware.AI.4180628677 also known as:

LionicTrojan.Win32.Swizzor.l78M
MicroWorld-eScanTrojan.Swizzor.Gen.7
FireEyeGeneric.mg.056965ece9c05014
CAT-QuickHealTrojan.C2Lop.MUE.AL4
SkyhighBehavesLike.Win32.Generic.bc
ALYacTrojan.Swizzor.Gen.7
Cylanceunsafe
ZillyaTrojan.Swizzor.Win32.127888
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( f10003021 )
AlibabaTrojanDownloader:Win32/Swizzor.a98546d7
K7GWTrojan ( f10003021 )
BitDefenderThetaAI:Packer.B2F10D7920
VirITTrojan.Win32.X-Swizzor.CCJ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Swizzor.NDF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-219391
KasperskyTrojan.Win32.Swizzor.c
BitDefenderTrojan.Swizzor.Gen.7
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentWin32.Trojan.Swizzor.Pgil
SophosMal/Swizzor-K
F-SecureTrojan.TR/Dldr.Swizzor.Gen2
DrWebTrojan.Swizzor.based
VIPRETrojan.Swizzor.Gen.7
TrendMicroMal_Swizzor-2
EmsisoftTrojan.Swizzor.Gen.7 (B)
MAXmalware (ai score=100)
GDataTrojan.Swizzor.Gen.7
JiangminTrojan/Obfuscated.Gen.b
GoogleDetected
AviraTR/Dldr.Swizzor.Gen2
VaristW32/Swizzor.D!Generic
Antiy-AVLTrojan/Win32.Swizzor
KingsoftWin32.Troj.SwizzorsT.ty
XcitiumTrojWare.Win32.TrojanDownloader.Swizzor.Gen@1fy3o0
ArcabitTrojan.Swizzor.Gen.7
ZoneAlarmTrojan.Win32.Swizzor.c
MicrosoftTrojan:Win32/C2Lop.N
CynetMalicious (score: 100)
McAfeeSwizzor.gen.g
TACHYONTrojan/W32.Swizzor.721408.M
DeepInstinctMALICIOUS
VBA32BScope.Trojan.BugsWay.H.Obfs
MalwarebytesMalware.AI.4180628677
TrendMicro-HouseCallMal_Swizzor-2
RisingTrojan.C2Lop!8.74A (TFE:5:LV1NM16GlzO)
YandexTrojan.Swizzor.Gen!Pac.6
IkarusVirus.Trojan.Win32.Obfuscated
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Swizzor.fam!tr
PandaTrj/Swizzor.S
alibabacloudTrojan[downloader]:Win/Swizzor.NDF

How to remove Malware.AI.4180628677?

Malware.AI.4180628677 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment