Malware

How to remove “Malware.AI.4187659407”?

Malware Removal

The Malware.AI.4187659407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4187659407 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family

How to determine Malware.AI.4187659407?


File Info:

name: 5538AD8DB1920BBC0E15.mlw
path: /opt/CAPEv2/storage/binaries/cad56c004b7f98ef33b1e3a569a8b3ca77ccb71718841d5b7b743c295480d00e
crc32: C1D7C0A7
md5: 5538ad8db1920bbc0e155d12bb94c6ff
sha1: 110173274a5b04e580981bc1c349c6dab6f4e977
sha256: cad56c004b7f98ef33b1e3a569a8b3ca77ccb71718841d5b7b743c295480d00e
sha512: 6b02b161aa4549376f94de6e26059e0eff25b21231c11ff95404e6535e0bb3d0dccda4d8e694099deb7ebf3e60065eadbcae7db63ee65066dac59846befeaa21
ssdeep: 12288:w+n+Nqdn8W+k5wJCpBHCESLMOQCU30PN4vZF0ePTGEaKkNRENHP+:gNmNeJCppCEVO7F4v0ePTbcehP+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFC423E06616C1A2C6424E715715E32F7368FA4043389623B7E2BF4F67B94F0322BE59
sha3_384: de6ca33619e07795fe8ba40e77af45194aabb350a985e2a56205443a791239574ad1a16f26f1150d8e52c2b6c994beea
ep_bytes: 0f8e33dfffff68a863aa4360c744241c
timestamp: 2019-11-23 04:55:11

Version Info:

Comments:
CompanyName:
FileDescription: PatchPKPM2010 V51 Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: PatchPKPM2010 V51
LegalCopyright: 版权所有 (C) 2011
LegalTrademarks:
OriginalFilename: PatchPKPM2010 V51.EXE
PrivateBuild:
ProductName: PatchPKPM2010 V51 应用程序
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Malware.AI.4187659407 also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.5538ad8db1920bbc
McAfeeArtemis!5538AD8DB192
CylanceUnsafe
VIPREGen:Variant.Jaik.81544
SangforTrojan.Win32.Agent.Volt
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Jaik.81544
MicroWorld-eScanGen:Variant.Jaik.81544
Ad-AwareGen:Variant.Jaik.81544
EmsisoftGen:Variant.Jaik.81544 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Jaik.81544
WebrootW32.Malware.Gen
MAXmalware (ai score=81)
ArcabitTrojan.Jaik.D13E88
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.Generic.C3658378
ALYacGen:Variant.Jaik.81544
MalwarebytesMalware.AI.4187659407
TrendMicro-HouseCallTROJ_GEN.R02CH09JL21
RisingTrojan.Generic@AI.96 (RDMK:4/YyUNGV1rkAU+2Mfxar4Q)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74748489.susgen
BitDefenderThetaGen:NN.ZexaF.34606.Ky0@ayBKTPob
Cybereasonmalicious.db1920
PandaTrj/CI.A

How to remove Malware.AI.4187659407?

Malware.AI.4187659407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment