Malware

Malware.AI.1573047027 information

Malware Removal

The Malware.AI.1573047027 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1573047027 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A scripting utility was executed
  • Attempts to remove evidence of file being downloaded from the Internet
  • Code injection with CreateRemoteThread in a remote process
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Malware.AI.1573047027?


File Info:

crc32: 7EB243DA
md5: afe4fae95415a21eb5ede20e137e0fa9
name: AFE4FAE95415A21EB5EDE20E137E0FA9.mlw
sha1: 71d78375c8e6e286b89e356f8bc82c3087eb799f
sha256: acd8405fde30044447831561fd507d7e166936c3c8026c349b24dc7a83c0ad48
sha512: 93998dfa09c34df4bc1ace5be67188924e1c8073e25041d2d1e99f8aebd5b8268517f089f6b548332327c381fcc17297b2b06f53f8187b8511e35333ed309585
ssdeep: 6144:2dgLDs1IAuaZDcppZebWyhYmhTsYLl8v7pqFETv+AqW/ExaXwhp2U5Ouk/PCJDr:2qDs1puagZoWeV1QpqJaY2483C1J
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) 2000-2019 Martin Prikryl
CompanyName: Martin Prikryl
FileDescription: WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
ProductVersion: 5.15.2.0
ProductName: WinSCP
Translation: 0x0409 0x0514

Malware.AI.1573047027 also known as:

K7AntiVirusTrojan ( 0056ef3d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.11130
McAfeeRDN/Generic.rp
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3107254
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/Tnega.90d1681b
K7GWTrojan ( 0056ef3d1 )
Cybereasonmalicious.95415a
CyrenW32/Kryptik.BKJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GXKQ
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Streamer.gen
BitDefenderGen:Variant.Zusy.345826
NANO-AntivirusTrojan.Win32.Inject4.ivltka
MicroWorld-eScanGen:Variant.Zusy.345826
Ad-AwareGen:Variant.Zusy.345826
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Dropper.bt
FireEyeGeneric.mg.afe4fae95415a21e
EmsisoftGen:Variant.Zusy.345826 (B)
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Tnega.BD!MTB
ArcabitTrojan.Zusy.D546E2
ZoneAlarmHEUR:Trojan.Win32.Streamer.gen
GDataGen:Variant.Zusy.345826
AhnLab-V3Malware/Win32.RL_Generic.R342422
VBA32Trojan.Inject
MAXmalware (ai score=86)
MalwarebytesMalware.AI.1573047027
PandaTrj/GdSda.A
YandexTrojan.Kryptik!b8k7lxMFPUQ
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.1573047027?

Malware.AI.1573047027 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment