Malware

Malware.AI.4241978905 (file analysis)

Malware Removal

The Malware.AI.4241978905 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4241978905 virus can do?

  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Malware.AI.4241978905?


File Info:

crc32: ECC36B5D
md5: 658f4b709dfb3b1da714a318e892d566
name: 658F4B709DFB3B1DA714A318E892D566.mlw
sha1: af206d2ba51edbaf164c10138f25ddbe35703d62
sha256: 24b071165591e9c6790e72925a51d8fa75f9fe465bb48b990a67ded70e93780d
sha512: 9b1f82a812f543ab491e58ea31c3eefb793a5d227fc520c9e0d4dbf961dbc45be2dbd7782f57368b6e4534db5757e49d92f623bfd2dfefd38526cf4461de0ef6
ssdeep: 24576:3cwIo8zP190yETUcpYIFNcMdiwQCN9pdZGAUamfcAE6pAWrQpz:MFoi2AyXcCQCN9xXmfpQp
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright microtech.co.uk
FileVersion: 12.7601.0.811
CompanyName: www.microtech.co.uk
ProductName: Defrag
ProductVersion: 12.7601.0.811
FileDescription: Disk Defragmenter
OriginalFilename: Defrag.exe
Translation: 0x0000 0x04b0

Malware.AI.4241978905 also known as:

K7AntiVirusTrojan ( 0051918e1 )
LionicTrojan.Win32.CoinMiner.4!c
Elasticmalicious (high confidence)
ALYacGeneric.Dacic.1.BitCoinMiner.A.D3479837
CylanceUnsafe
AlibabaTrojan:Win32/Miners.8e44be0f
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.09dfb3
SymantecTrojan Horse
ESET-NOD32a variant of Win32/CoinMiner.FX potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGeneric.Dacic.1.BitCoinMiner.A.D3479837
MicroWorld-eScanGeneric.Dacic.1.BitCoinMiner.A.D3479837
Ad-AwareGeneric.Dacic.1.BitCoinMiner.A.D3479837
BitDefenderThetaGen:NN.ZexaF.34266.HnKfaG3NG!ni
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.Win32.XMRig.AA
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.Dacic.1.BitCoinMiner.A.D3479837
EmsisoftGeneric.Dacic.1.BitCoinMiner.A.D3479837 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASCommon.203
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitGeneric.Dacic.1.BitCoinMiner.A.D3479837
GDataGeneric.Dacic.1.BitCoinMiner.A.D3479837
AhnLab-V3Trojan/Win32.CoinMiner.C2637743
McAfeeArtemis!658F4B709DFB
MAXmalware (ai score=91)
VBA32BScope.Trojan.Miner
MalwarebytesMalware.AI.4241978905
PandaTrj/CI.A
TrendMicro-HouseCallPUA.Win32.XMRig.AA
IkarusPUA.CoinMiner
FortinetRiskware/CoinMiner
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4241978905?

Malware.AI.4241978905 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment