Malware

Malware.AI.128536692 removal instruction

Malware Removal

The Malware.AI.128536692 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.128536692 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk

How to determine Malware.AI.128536692?


File Info:

crc32: EFEB18C7
md5: a64992bb77f78260ec89083da3ba2b35
name: A64992BB77F78260EC89083DA3BA2B35.mlw
sha1: 6673a295b96815d91e29021f90955671523ff4f2
sha256: f6d77a5975fe01073b3fee8559c7f2be34c03a4560fa8ffabd671d4021a7dfad
sha512: 35bfaf56fc1b815d908b56a8d6d70c76d7ca42024c6a3bb1133487486a88c059f58cc7fcb6e4aacb4738f8030d9fe4caa17cfd9ffefc7bf612c59d873949b779
ssdeep: 24576:7Oih4N1P2aaxIHSOOQwKJiny9dv/oz6xQqAxLWSSxmZAf+P3aa8Vb08Iytv+yHT:yiU2aaxIHSGqL9ZACQWw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: Windows
ProductVersion: 1.0.0.0
FileDescription: Microsoft Corporation
Translation: 0x0804 0x04b0

Malware.AI.128536692 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.BtcMine.3404
MicroWorld-eScanGen:Variant.Graftor.452343
ALYacGen:Variant.Graftor.452343
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.b77f78
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.QQPass.OZV
APEXMalicious
AvastOther:Malware-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderGen:Variant.Graftor.452343
TencentWin32.Trojan.Generic.Llgz
Ad-AwareGen:Variant.Graftor.452343
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34688.tv0@aKIj13ab
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.a64992bb77f78260
EmsisoftGen:Variant.Graftor.452343 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Application.PUPStudio.A
AhnLab-V3Trojan/Win.Generic.C4465687
McAfeeArtemis!A64992BB77F7
MAXmalware (ai score=83)
VBA32BScope.Trojan.Dynamer
MalwarebytesMalware.AI.128536692
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazpspJuR0OpYKXdpdV5zp+nD)
IkarusTrojan-PSW.QQpass
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/QQPass
AVGOther:Malware-gen [Trj]

How to remove Malware.AI.128536692?

Malware.AI.128536692 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment