Malware

What is “Malware.AI.1526770693”?

Malware Removal

The Malware.AI.1526770693 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1526770693 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1526770693?


File Info:

crc32: CFF9A1E4
md5: ef22608568722a79aa5c23f4c4aeb348
name: EF22608568722A79AA5C23F4C4AEB348.mlw
sha1: 0c4b54ef3af64c5da365f8e4ed583ecd1cbc3163
sha256: 1e0d6f899528b82009bf4415ea22646ced45b49fb429bf4f88237631d63488ae
sha512: f69404c68f4c08dc0e229f326555b1d81f5e02cbecd78e0e267779e992b851da41a29da82db3f21e9e55e5991038ce7319273baf5e28e099963eb8d38e04e64a
ssdeep: 6144:BcfLrZxJN8qNH9LWpKNkX0NlUFyjwbu5p9VHZ+jziJww1JoM:ENrH9hk5Fyjbp75luk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Xanif. All rights reserved. 2017
InternalName: Xanifer
FileVersion: 1.0.0.6
CompanyName: Xanif Ltd.
ProductName: Xanifxae Inform
ProductVersion: 1.0.0.6
FileDescription: Xanif Ltd. Gui application
OriginalFilename: Xanif
Translation: 0x0409 0x04b1

Malware.AI.1526770693 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005380d91 )
Elasticmalicious (high confidence)
DrWebTrojan.Trick.46147
MicroWorld-eScanGen:Variant.Graftor.503710
ALYacGen:Variant.Graftor.503710
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1465004
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/MereTam.ali2000008
K7GWTrojan ( 005380d91 )
Cybereasonmalicious.568722
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJAZ
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.503710
NANO-AntivirusTrojan.Win32.Inject.ffpwrl
TencentMalware.Win32.Gencirc.10cb1834
Ad-AwareGen:Variant.Graftor.503710
SophosMal/Generic-R + Mal/EncPk-ANZ
ComodoMalware@#1w8cf6ibu081g
BitDefenderThetaGen:NN.ZexaF.34266.Eq0@a0lFMZei
TrendMicroTrojanSpy.Win32.TRICKBOT.SMB
McAfee-GW-EditionTrojan-FPOJ!EF2260856872
FireEyeGeneric.mg.ef22608568722a79
EmsisoftGen:Variant.Graftor.503710 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.aozj
WebrootTrojan.Spy.Trickbot
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.270D6A1
MicrosoftTrojan:Win32/MereTam.A
ArcabitTrojan.Graftor.D7AF9E
GDataGen:Variant.Graftor.503710
TACHYONTrojan/W32.Inject.503808.W
AhnLab-V3Malware/Win32.Generic.C2651489
McAfeeTrojan-FPOJ!EF2260856872
MAXmalware (ai score=100)
VBA32BScope.Trojan.Inject
MalwarebytesMalware.AI.1526770693
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMB
RisingTrojan.Generic@ML.100 (RDML:5tjK88ljTtFKjLsJNTOTIg)
YandexTrojan.GenAsa!uMtxarIoLew
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.CFOA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1526770693?

Malware.AI.1526770693 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment