Malware

What is “Malware.AI.1325440450”?

Malware Removal

The Malware.AI.1325440450 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1325440450 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed analysis tools by a known file location
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1325440450?


File Info:

crc32: F49E08EE
md5: be074d86fdf6adddffe4bb58827d152a
name: BE074D86FDF6ADDDFFE4BB58827D152A.mlw
sha1: 09db7a56e01d7571421df9dfbe02ec27e933ad6c
sha256: 411a40b3f2bc2cb5e40ec1f7980821e497d0e8d4df163e2f16c94189092b3089
sha512: dfa014cf351c3d73d3645475e7ee59bf29fbd035c8a47161a094a9d017243892306b6adf08f52d990d19d582fca59f9b218e0b238a31c962e287439c7036c598
ssdeep: 12288:XAHMrpQy/54sxysNYSS+3BJbNjZ7Afysn/2GuPMwpHTr:ws5/5bx1nxXZEfys/XuEWHv
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: gfdfsd sdfdf sfsdsqsa
Assembly Version: 6.2.136.0
InternalName: r.exe
FileVersion: 6.2.136.0
CompanyName: gfdfsd sdfdf sfsdsqsa
Comments: gfdfsd sdfdf sfsdsqsa
ProductName: gfdfsd sdfdf sfsdsqsa
ProductVersion: 6.2.136.0
FileDescription: gfdfsd sdfdf sfsdsqsa
OriginalFilename: r.exe

Malware.AI.1325440450 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader17.57113
CynetMalicious (score: 99)
ALYacGen:Trojan.Heur.DNP.7q0@aW87@tp
CylanceUnsafe
ZillyaTrojan.Injector.Win32.765307
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.7f7fbaa7
K7GWTrojan ( 700000121 )
Cybereasonmalicious.6fdf6a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.MND
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.hyhf
BitDefenderGen:Trojan.Heur.DNP.7q0@aW87@tp
NANO-AntivirusTrojan.Win32.Blocker.hssnsx
MicroWorld-eScanGen:Trojan.Heur.DNP.7q0@aW87@tp
TencentMsil.Trojan.Injector.Pfsx
Ad-AwareGen:Trojan.Heur.DNP.7q0@aW87@tp
SophosMal/Generic-S
ComodoMalware@#125tz5qxc25zw
F-SecureTrojan.TR/Dropper.MSIL.Gen
BitDefenderThetaAI:Packer.EA46C4D01F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.be074d86fdf6addd
EmsisoftGen:Trojan.Heur.DNP.7q0@aW87@tp (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Heur.bby
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Heur.DNP.ED174EC
ZoneAlarmTrojan-Ransom.Win32.Blocker.hyhf
GDataGen:Trojan.Heur.DNP.7q0@aW87@tp
AhnLab-V3Malware/Gen.RL_Generic.C3512058
McAfeeArtemis!BE074D86FDF6
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.1325440450
PandaTrj/CI.A
YandexTrojan.Injector!a5UWbZSRpyI
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/MND!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1325440450?

Malware.AI.1325440450 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment