Adware

Adware.Heur.mmKfN8Zdmlai malicious file

Malware Removal

The Adware.Heur.mmKfN8Zdmlai is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Heur.mmKfN8Zdmlai virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Adware.Heur.mmKfN8Zdmlai?


File Info:

crc32: 88BC16DB
md5: 636dac96a13681977ff0f1e4d0d380ab
name: 636DAC96A13681977FF0F1E4D0D380AB.mlw
sha1: 6358b4aa1d0fd766d652b399fdd04442ac860e6a
sha256: a7e1f7595c6e77f13f655ef3b2d12c152eeeb6e191a465bfc81cb0cbe8313e7a
sha512: b8cf8397040d39f7147ae20e11eea28ebac67e1cf1593795a558f95fda1145d647ef3072aed7d33de720642644f95fd9c898bd15d5f8558c8edd95735747f6bc
ssdeep: 3072:ji9UPksR5P/HKjAQy8i8D2Bu/BlSx16EFNOKd2ylyyNAvYiKf:cSkk5PPKgiDFJYx19NOo2y8yNAvY
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2021
ProductVersion: 2.1.0.0
ProductName: SecurityImprover
FileVersion: 2.1.0.0
FileDescription: SecurityImprover
Translation: 0x040c 0x04e4

Adware.Heur.mmKfN8Zdmlai also known as:

K7AntiVirusTrojan ( 00549d461 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Adware.Heur.mmKfN8Zdmlai
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 00549d461 )
Cybereasonmalicious.6a1368
BaiduWin32.Adware.Generic.bo
ESET-NOD32a variant of Win32/Filecoder.ODM
APEXMalicious
AvastWin32:Dh-A [Heur]
BitDefenderGen:Adware.Heur.mmKfN8Zdmlai
NANO-AntivirusTrojan.Win32.FileCoder.iioefr
MicroWorld-eScanGen:Adware.Heur.mmKfN8Zdmlai
Ad-AwareGen:Adware.Heur.mmKfN8Zdmlai
BitDefenderThetaGen:NN.ZexaF.34686.mmKfa8Zdmlai
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.636dac96a1368197
EmsisoftGen:Adware.Heur.mmKfN8Zdmlai (B)
JiangminTrojan.Gen.bfp
MicrosoftRansom:Win32/FileCoder.SG!MTB
GDataGen:Adware.Heur.mmKfN8Zdmlai
TACHYONRansom/W32.SunCrypt.592384
MAXmalware (ai score=61)
VBA32BScope.TrojanRansom.Gen
RisingRansom.Gen!8.DE83 (TFE:4:5B0edYvjYlD)
AVGWin32:Dh-A [Heur]

How to remove Adware.Heur.mmKfN8Zdmlai?

Adware.Heur.mmKfN8Zdmlai removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment