Malware

Malware.AI.106201880 (file analysis)

Malware Removal

The Malware.AI.106201880 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.106201880 virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
fruitnext.top
caribz.club

How to determine Malware.AI.106201880?


File Info:

crc32: 9AFE2959
md5: 347e5835db6b5838a82abcd6e3ca26d2
name: 347E5835DB6B5838A82ABCD6E3CA26D2.mlw
sha1: 3cae906d3e11a506ed52bac03f49ddb10e06dc6f
sha256: 1e090b5d53f329f730bf821442b274362104ba106024209b38b5c3433ed290f9
sha512: 99c4df9930977518f6fe6b8141c4f8b0b36b8169710019c433efc96c4d7e81e526fb4f195ac4fa23bca476753c118d6612ebcfe30f5274d90d7d80fcb2ce85cd
ssdeep: 6144:eo4UWvWoCzqxw6ZoUetbdoK32gJ3ydAea8cZnihGN0nQT1cCU:0+oCzGkIK3p3QAea8SniEN6Q5g
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

Comments: q v b s g xInstalls software 32
Translation: 0x0409 0x04b0

Malware.AI.106201880 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 00520c311 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.9530
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5252205
ALYacTrojan.GenericKD.12765287
CylanceUnsafe
ZillyaDownloader.Agent.Win32.446258
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 00520c311 )
Cybereasonmalicious.5db6b5
CyrenW32/Tovkater.L
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Tovkater.IC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Tovkater-6956309-0
KasperskyTrojan-Downloader.Win32.Tovkater.carb
BitDefenderTrojan.GenericKD.12765287
NANO-AntivirusRiskware.Win32.InstMonster.ewnofw
MicroWorld-eScanTrojan.GenericKD.12765287
TencentWin32.Trojan-downloader.Tovkater.Ljas
Ad-AwareTrojan.GenericKD.12765287
SophosMal/Generic-S (PUA)
ComodoMalware@#188ky4tdkc6u6
BitDefenderThetaGen:NN.ZexaF.34266.JmGfaGjiURbG
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJB21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.347e5835db6b5838
EmsisoftTrojan.GenericKD.12765287 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117983
eGambitUnsafe.AI_Score_64%
Antiy-AVLTrojan/Generic.ASMalwS.347A13C
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Generic.DC2C867
GDataNSIS.Trojan-Downloader.Tovkater.C
AhnLab-V3Downloader/Win32.Tovkater.R359673
Acronissuspicious
McAfeeArtemis!347E5835DB6B
MAXmalware (ai score=80)
VBA32TrojanDownloader.Tovkater
MalwarebytesMalware.AI.106201880
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJB21
RisingDownloader.Tovkater/NSIS!1.AF36 (CLASSIC)
YandexTrojan.GenAsa!qhYl4EpQjKc
FortinetW32/Tovkater.IA!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.106201880?

Malware.AI.106201880 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment