Malware

Malware.AI.1327915634 removal guide

Malware Removal

The Malware.AI.1327915634 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1327915634 virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1327915634?


File Info:

crc32: 048A9B2B
md5: fdd1bb81f7b6c04a356ed686c2e8e19f
name: FDD1BB81F7B6C04A356ED686C2E8E19F.mlw
sha1: df673b7441fd55da3b344de519da837e5cc55f56
sha256: e820437bd8eb8f6e1fd6992c902e57cb3c3f8176ec646eb2a04fe0953bcbae10
sha512: 0d7371b070fda04619cfe4fe6d9273e33ce2d2923bcf5c8da42b301ac8774ab34aff99021283d09de03fd06371136822651c807c376cce0f4ab9faea44e79221
ssdeep: 6144:83JsKfDwrcxFVJDaCF2w68CAITV+KjwOkJiW6O0q2HezCEfAqp:qsKfYWVJGCF2eClTV+KkfqO0q2+zV3
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: Phoenix Atmega Loader v2.7.6
FileVersion: 2.07.0006
CompanyName: The Unknowns
ProductName: Phoenix Atmega Loader
ProductVersion: 2.07.0006
OriginalFilename: Phoenix Atmega Loader v2.7.6.exe

Malware.AI.1327915634 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop7.63876
CynetMalicious (score: 99)
CylanceUnsafe
SangforTrojan.Win32.Generik.LVMPWUJ
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.441fd5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LVMPWUJ
APEXMalicious
AvastWin32:Malware-gen
NANO-AntivirusTrojan.Win32.Johnnie.exbczl
TencentWin32.Trojan.Dropper.Eibh
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0PIG21
McAfee-GW-EditionBehavesLike.Win32.Trojan.fc
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!FDD1BB81F7B6
MAXmalware (ai score=95)
VBA32BScope.Trojan.MulDrop
MalwarebytesMalware.AI.1327915634
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R067C0PIG21
MaxSecureTrojan.Malware.300983.susgen
FortinetGenericRXDC.YR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1327915634?

Malware.AI.1327915634 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment