Malware

Malware.AI.1316680576 removal tips

Malware Removal

The Malware.AI.1316680576 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1316680576 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
mezendracr.com

How to determine Malware.AI.1316680576?


File Info:

crc32: 8A261115
md5: 05ea5ceb4e3aa2f136da01e1f0144876
name: 05EA5CEB4E3AA2F136DA01E1F0144876.mlw
sha1: 6d7328b3a93aa348e9e9a04a31794b48b3cdc92c
sha256: 1dc5f31bcc79efa7a6de7b605521e39cb39a77f2cf629b422fc8149670cbcd12
sha512: 555c2aac8167502f4028c33e0bb56695b89200587ad8b3d12f1aeaa18f898925613e81d8e73666e13214beea33ca68d3e21b46ccc855f98a7a34955c6005df19
ssdeep: 49152:X6KOelzvlI7uK2UwY0/KcnTUXN8hGuYeVAfF2C26XkYRW4abu7/TNVirsdp:X6KOMvlIKKcYLAw26Xl8ujTN8rsdp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2001 Orange Legal Technologies Forest. All rights reserved
InternalName: Addanswer
CompanyName: Orange Legal Technologies Forest
ProductName: Addanswer
ProductVersion: 8.5.69.33
FileDescription: Addanswer
OriginalFilename: bitside.exe
Translation: 0x0409 0x04b0

Malware.AI.1316680576 also known as:

K7AntiVirusSpyware ( 00538dab1 )
LionicTrojan.Win32.Ursnif.tpCd
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.28481
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Tiggre.S4410650
ALYacTrojan.Agent.DJQZ
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1022076
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanSpy:Win32/Ursnif.54d5d2dd
K7GWSpyware ( 00538dab1 )
Cybereasonmalicious.b4e3aa
CyrenW32/S-4733b24d!Eldorado
SymantecInfostealer
ESET-NOD32Win32/Spy.Ursnif.BW
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.File.Sodinokibi-9779217-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.DJQZ
NANO-AntivirusTrojan.Win32.Ursnif.fkpitl
MicroWorld-eScanTrojan.Agent.DJQZ
TencentMalware.Win32.Gencirc.10b235ac
Ad-AwareTrojan.Agent.DJQZ
SophosMal/Generic-S
ComodoTrojWare.Win32.Tiggre.BW@7y3xhc
BitDefenderThetaGen:NN.ZexaF.34266.Vz0@aOT4hEji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-FOP!05EA5CEB4E3A
FireEyeGeneric.mg.05ea5ceb4e3aa2f1
EmsisoftTrojan-Spy.Ursnif (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Ursnif.buw
AviraHEUR/AGEN.1118297
Antiy-AVLTrojan/Generic.ASMalwS.2990972
MicrosoftTrojanSpy:Win32/Ursnif.IG!bit
ArcabitTrojan.Agent.DJQZ
SUPERAntiSpywareTrojan.Agent/Gen-Ursnif
GDataTrojan.Agent.DJQZ
TACHYONTrojan-Spy/W32.Ursnif.1829376
AhnLab-V3Trojan/Win32.Ursnif.R245884
Acronissuspicious
McAfeePacked-FOP!05EA5CEB4E3A
MAXmalware (ai score=82)
VBA32TrojanSpy.Ursnif
MalwarebytesMalware.AI.1316680576
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.91 (RDMK:Zy8Oz+tNGuJlj+8IcEn5FQ)
YandexTrojan.GenAsa!CZS0bihdKEQ
IkarusTrojan.Win32.Ursnif
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Ursnif.BW!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.1316680576?

Malware.AI.1316680576 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment