Malware

Malware.AI.4241126489 removal tips

Malware Removal

The Malware.AI.4241126489 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4241126489 virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Malware.AI.4241126489?


File Info:

name: 8C119735AF67BFF7802D.mlw
path: /opt/CAPEv2/storage/binaries/45f11e113f471b83aa89f0d0f94f633f9b585b8a6623db45b9ea8ecaf9086933
crc32: A9E06DF8
md5: 8c119735af67bff7802d44e7602ca960
sha1: bacc47969454f8b12bc87a069645747f522f83e5
sha256: 45f11e113f471b83aa89f0d0f94f633f9b585b8a6623db45b9ea8ecaf9086933
sha512: 474ab37bd8b7698cc6d94e8cd9ede5f0128133f018b1d00cbcc782c53f7f6d2ebc71f741c8887189e2170371a0aff278e2d536877eee1570f97491e54293977a
ssdeep: 98304:a9Lm1gy0m2gBLEbdERBfH2qsWeC5x2SqjKtU0kBU/8SjvXI+EEWQ5PEl+qoyL/uv:ecgyX2gKREBfH25W3HKXII7k5PElouK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163C67E13B744553EC4AB5A3B9C37E784B83FBA612A068E1767F4094C4F397806B3A647
sha3_384: 794dfdab483d513889f0aa29e798b5c09e0e2efc5141425ca77a93de8879a2877b4b7e6e9efc9c584dcab6795c30b3ca
ep_bytes: 558bec83c4f0b8609ad900e8846165ff
timestamp: 2019-07-03 18:16:09

Version Info:

CompanyName: Мiсrоsоft Соrpоrаtiоn
FileDescription: Ноst Рrосеss fоr Windоws Sеrviсеs
FileVersion: 21.0.340401.4 (WinBuild.235042.0970)
InternalName: svchоst.exe
LegalCopyright: © Мiсrоsоft Соrроrаtiоn. Аll rights rеsеrvеd.
OriginalFilename: svchоst.exe
ProductName: Мiсrоsоft® Windоws® Ореrаting Sуstеm
ProductVersion: 21.0.340401.4
Translation: 0x0409 0x04b0

Malware.AI.4241126489 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Siggen9.17172
MicroWorld-eScanApplication.Generic.3066602
ALYacApplication.Generic.3066602
CylanceUnsafe
ZillyaTrojan.Generic.Win32.966092
SangforTrojan.Win32.Generic.ky
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RemoteAdmin.RemoteUtilities.X potentially unsafe
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.Generic.3066602
NANO-AntivirusTrojan.Win32.RemoteAdmin.iyvmcq
Ad-AwareApplication.Generic.3066602
SophosGeneric PUA LK (PUA)
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeApplication.Generic.3066602
EmsisoftApplication.Generic.3066602 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.eailr
MAXmalware (ai score=73)
Antiy-AVLTrojan/Generic.ASMalwS.2C573E5
MicrosoftPUA:Win32/Puamson.A!ml
ArcabitApplication.Generic.D2ECAEA
GDataWin32.Trojan.RMS.B
AhnLab-V3Malware/Win.Generic.C4634452
McAfeeGenericRXAA-AA!8C119735AF67
VBA32Trojan.Wacatac
MalwarebytesMalware.AI.4241126489
YandexTrojan.Agent!vEsAnj5mYck
IkarusPUA.RemoteUtilities
FortinetRiskware/RemoteAdmin_RemoteUtilities

How to remove Malware.AI.4241126489?

Malware.AI.4241126489 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment