Malware

Malware.AI.1313885310 removal tips

Malware Removal

The Malware.AI.1313885310 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1313885310 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1313885310?


File Info:

crc32: 5E39F51F
md5: 256eb3ab4c1191e330b4321dcf18627d
name: 256EB3AB4C1191E330B4321DCF18627D.mlw
sha1: e1821c6d0232f752848884afd36757082416ea15
sha256: a28ff6be0339b136aa52a8ceeeee2d3abcb9f2e0ddd760a6734b9eb9d3c1826b
sha512: 12a3cc56673707c601e3f3742402641156ae8f20401289a382500c5511a30d4c537555d6948bc27dae4b61e8cc86e4d34ffa3257b05986ebb130bffc9bf08dda
ssdeep: 6144:06nion8hTpSXXmn2jZcXJfD9dLWkZzWT8Wuom4meT2Cqx:Tn8hTS4XJZ0kiuaT2Cqx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9. All rights reserved. Cylance
InternalName: CupsSqldatetimn
FileVersion: 4.5.6.2
CompanyName: Cylance
ProductName: CupsSqldatetimn
ProductVersion: 4.5.6.2
FileDescription: Artifactlinkids Intising Merchandise Contrast
Translation: 0x0409 0x04b0

Malware.AI.1313885310 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004d3dc91 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.18284
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.73878
CylanceUnsafe
ZillyaTrojan.Delf.Win32.127934
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Foreign.5932bbfa
K7GWTrojan ( 004d3dc91 )
Cybereasonmalicious.b4c119
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.ATW
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyTrojan-Ransom.Win32.Foreign.nmey
BitDefenderGen:Variant.Symmi.73878
NANO-AntivirusTrojan.Win32.Delf.enwbho
MicroWorld-eScanGen:Variant.Symmi.73878
TencentWin32.Trojan.Foreign.Hqcc
Ad-AwareGen:Variant.Symmi.73878
SophosMal/Generic-S
ComodoMalware@#10l4lk6yw5bq8
BitDefenderThetaGen:NN.ZexaF.34692.yq1@ampvuJii
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMJAL
McAfee-GW-EditionBehavesLike.Win32.Downloader.fc
FireEyeGeneric.mg.256eb3ab4c1191e3
EmsisoftGen:Variant.Symmi.73878 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.cjx
AviraTR/AD.Inject.spugs
Antiy-AVLTrojan/Generic.ASMalwS.204CAEC
MicrosoftTrojan:Win32/Satbrop.A
ArcabitTrojan.Symmi.D12096
AegisLabTrojan.Win32.Foreign.trsP
ZoneAlarmTrojan-Ransom.Win32.Foreign.nmey
GDataGen:Variant.Symmi.73878
AhnLab-V3Win-Trojan/Sagecrypt.Gen
Acronissuspicious
McAfeeArtemis!256EB3AB4C11
MAXmalware (ai score=100)
VBA32Hoax.Foreign
MalwarebytesMalware.AI.1313885310
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.SMJAL
RisingTrojan.Generic@ML.98 (RDML:lyL46ZzTzaS9Wazd6RUevQ)
YandexTrojanSpy.Zbot!rJCN+hQGzNE
IkarusTrojan-Ransom.GandCrab
FortinetW32/Delf.ATW!tr
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml

How to remove Malware.AI.1313885310?

Malware.AI.1313885310 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment