Malware

What is “Malware.AI.1266561579”?

Malware Removal

The Malware.AI.1266561579 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1266561579 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system

Related domains:

narotomagic.publicvm.com

How to determine Malware.AI.1266561579?


File Info:

crc32: 9625F2D1
md5: 753c707e47bce65d32be781ea1584e0b
name: 753C707E47BCE65D32BE781EA1584E0B.mlw
sha1: 7b43f6a910b01553dfae51560570365e3ce9ed42
sha256: b1c0e35f47273a236518f43ee56c0367d8b423ca9ed8f9e7ad4a875caa47bb69
sha512: 8afc2ebbc80e17e42317202e9479e0c223456cf9f0b22ccdf9fe486eff19ebf9a33a2e00c01aa81168d4ad9950c34c8d78dc2f5821702fe61874221088d3cdda
ssdeep: 1536:2ppfa5dJy8Cgrw7rPNDwhucaDlZ5gb0HI//4gQF0eCaL:3yIwmhuDlZWbcO4/waL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: yg.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: yg.exe

Malware.AI.1266561579 also known as:

K7AntiVirusTrojan ( 004b8af71 )
LionicTrojan.Win32.Generic.lWsG
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.15022
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.3.Gen
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004b8af71 )
Cybereasonmalicious.e47bce
CyrenW32/MSIL_Kryptik.VY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.BLX
APEXMalicious
AvastMSIL:GenMalicious-R [Trj]
KasperskyHEUR:Trojan.MSIL.RRAT.gen
BitDefenderTrojan.MSIL.Basic.3.Gen
MicroWorld-eScanTrojan.MSIL.Basic.3.Gen
Ad-AwareTrojan.MSIL.Basic.3.Gen
SophosMal/Generic-R
BitDefenderThetaAI:Packer.1D1870CD1F
TrendMicroTROJ_GEN.R014C0WH321
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
FireEyeGeneric.mg.753c707e47bce65d
EmsisoftTrojan.MSIL.Basic.3.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.MSIL.Basic.3.Gen
ZoneAlarmHEUR:Trojan.MSIL.RRAT.gen
GDataMSIL.Backdoor.Bladabindi.2M2T8A
AhnLab-V3Dropper/Win32.Habbo.C854622
McAfeeArtemis!753C707E47BC
MAXmalware (ai score=87)
MalwarebytesMalware.AI.1266561579
TrendMicro-HouseCallTROJ_GEN.R014C0WH321
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.BLX!tr
AVGMSIL:GenMalicious-R [Trj]
Qihoo-360HEUR/QVM03.0.341B.Malware.Gen

How to remove Malware.AI.1266561579?

Malware.AI.1266561579 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment