Malware

Malware.AI.2831016977 removal instruction

Malware Removal

The Malware.AI.2831016977 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2831016977 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
make.campzephyr.host
create.guitarchange.site

How to determine Malware.AI.2831016977?


File Info:

crc32: 24D9F34A
md5: 40032b9083c241f11817f9e6cac7e8f4
name: 40032B9083C241F11817F9E6CAC7E8F4.mlw
sha1: b4273056ab6a5c21b9ce255efb990813ab0e30f9
sha256: 1a4c34d7036b9ef779af11b00f4c931ad58953b28195cf2954385cacc80c3f42
sha512: 271bb751f6c738a7af10717a1ceaec083f69393cd2e409bd2bcab41609ecd1b85aaac8d47309290d32f6e3d4657f4ed8e767fb7eb2b212b0fde5a3d282cb3188
ssdeep: 24576:Vs+5PaBThTyCdW4yZZB1QE9rTwyrtqdA0D3VVZw8C73KE9Zinas+RrZhaCsD:VpPaB9eS8ZxtvSD3uVSF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Yunotty
InternalName: AFPABEANAFFUH.EXE
FileVersion: 1.0.9.3
CompanyName: xa9Yunotty
ProductName: AFPABEANAFFUH
ProductVersion: 1.0.9.3
OriginalFilename: afpabeanaffuh.exe
Translation: 0x0409 0x04e4

Malware.AI.2831016977 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053f6df1 )
LionicAdware.Win32.DownloadHelper.2!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.12212
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.DownloadHelper.Win32.1764
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/StartSurf.6ec76da9
K7GWTrojan ( 0053f6df1 )
Cybereasonmalicious.083c24
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.COQJ
APEXMalicious
AvastWin32:LoadMoney-ATT [Adw]
Kasperskynot-a-virus:UDS:AdWare.Win32.DownloadHelper.gen
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10cd417e
Ad-AwareGen:Heur.Mint.Zamg.1
SophosIStartSurfInstaller (PUA)
ComodoMalware@#35z9yhdd5qrya
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
BitDefenderThetaGen:NN.ZexaF.34236.As0@a0Dv5Bci
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Swizzor
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
FireEyeGeneric.mg.40032b9083c241f1
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DownloadHelper.bfl
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLGrayWare[AdWare]/Win32.DownloadHelper
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Mint.Zamg.1
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3PUP/Win32.DownloadHelper.R266696
Acronissuspicious
McAfeePacked-FKC!40032B9083C2
MAXmalware (ai score=99)
VBA32BScope.Adware.DownloadHelper
MalwarebytesMalware.AI.2831016977
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Swizzor
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.DownloadHelper!uWjt441h/Lw
IkarusPUA.Dlhelper
FortinetW32/Kryptik.GIQX!tr
AVGWin32:LoadMoney-ATT [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.2831016977?

Malware.AI.2831016977 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment