Malware

Malware.AI.4278007906 removal guide

Malware Removal

The Malware.AI.4278007906 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4278007906 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.4278007906?


File Info:

name: 56CFA55D5CD3CC8980DF.mlw
path: /opt/CAPEv2/storage/binaries/bc58e71bb01eb0d997431612e04433ac3e88a185fc67d52fbf1e168d6606fe3b
crc32: 88F951FB
md5: 56cfa55d5cd3cc8980df0759edbe9541
sha1: a073e2db74466d232306133b2833b5c518c43433
sha256: bc58e71bb01eb0d997431612e04433ac3e88a185fc67d52fbf1e168d6606fe3b
sha512: e100b5f0ec1ad5672887c19383f04ea6e8f6f1b373c50bb561ab4450fa52345fe8ec7a97f380ddcf7aaf1a2e1aa79d4b4fb9767e0fa954862f9896e418c7c34f
ssdeep: 24576:/nf7RG1BpRK8tYgWYOkNy8KmBohqRabU+DRZdC/hR:/n9kpgFpkaQ+Dz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F95D022F6918437D1332A7D4C3B9398986EBE201D3994477AE61E4C9F786C13D2E2D7
sha3_384: e8c5ab271f60312a9af91360153f99a19458b8358a25646dde1c5d6172d85b3affc944d6ed8629b886964688ab6fbf59
ep_bytes: 558becb9080000006a006a004975f9b8
timestamp: 2020-09-05 19:28:58

Version Info:

CompanyName: 761魔域登录器
FileDescription: 商业程序
InternalName: mydlq.exe
LegalCopyright: 版权所有 (C) 2010
OriginalFilename: LoginTools.exe
ProductName: 商业程序
ProductVersion: 1, 0, 0, 0
FileVersion: 1,0,0,0
Translation: 0x0804 0x03a8

Malware.AI.4278007906 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fugrafa.6351
FireEyeGeneric.mg.56cfa55d5cd3cc89
McAfeeGenericRXGA-BH!56CFA55D5CD3
CylanceUnsafe
Sangfor[ASPACK V2.12]
K7AntiVirusRiskware ( 0054406b1 )
K7GWRiskware ( 0054406b1 )
Cybereasonmalicious.d5cd3c
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/RiskWare.GameTool.T
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fugrafa.6351
NANO-AntivirusTrojan.Win32.Hosts.ihshyl
AvastWin32:MiscX-gen [PUP]
RisingMalware.Lmir!8.E96A (C64:YzY0OgV3GgE5TUxb6A)
Ad-AwareGen:Variant.Fugrafa.6351
SophosGeneric ML PUA (PUA)
DrWebTrojan.Hosts.48206
ZillyaTool.GameTool.Win32.1191
McAfee-GW-EditionBehavesLike.Win32.Dropper.tm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Fugrafa.6351 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1214757
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Fugrafa.6351
AhnLab-V3Unwanted/Win32.RL_GameHack.R368480
Acronissuspicious
BitDefenderThetaAI:Packer.C6B1A80219
ALYacGen:Variant.Fugrafa.6351
MAXmalware (ai score=82)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.4278007906
TencentRiskware.Win32.Gametool.16000348
YandexRiskWare.GameTool!7bLD9XIT1Jo
IkarusTrojan-Spy.Lmir
MaxSecureTrojan.Malware.74776291.susgen
FortinetW32/Lmir.BQT!tr
AVGWin32:MiscX-gen [PUP]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.4278007906?

Malware.AI.4278007906 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment