Malware

Malware.AI.1783480604 removal guide

Malware Removal

The Malware.AI.1783480604 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1783480604 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Attempts to disable browser security warnings

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com
oppnetter.biz.ua

How to determine Malware.AI.1783480604?


File Info:

crc32: 78D2133E
md5: c4c22e78df660448c4665a1e894d88fb
name: C4C22E78DF660448C4665A1E894D88FB.mlw
sha1: 48c1acd1a52498bf85c4b29a5eed5fc7a422f3d1
sha256: 67f97adfca84494284fc46157a0f9a715d237175d03da9774e07d65014e8c087
sha512: 2782cea20a3c4256f8751c2df0ca44a209b2fcf1315c3d76014ef12ba0231b2d3676828597fbc69d6472e14249603e54ff67a0b50b9f2bace5f5cd4fd576a371
ssdeep: 12288:RkxDoouVA2nxKkh0vdRgQriDJOIZW+yBGQowlNCONye3Dd6:bRmJkqoQrilOIQ+yMxyNye3Dd6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 0
FileVersion: 3, 3, 8, 0
FileDescription:
Translation: 0x0809 0x04b0

Malware.AI.1783480604 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0047e7591 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.AVKill.24742
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.43893131
CylanceUnsafe
ZillyaTrojan.Diztakun.Win32.2475
K7GWTrojan ( 0047e7591 )
Cybereasonmalicious.8df660
SymantecTrojan.Ransomlock.V
ESET-NOD32a variant of Win32/LockScreen.BAJ
APEXMalicious
AvastAutoIt:LockScreen-A [Trj]
BitDefenderTrojan.GenericKD.43893131
NANO-AntivirusTrojan.Win32.AVKill.ecehvr
MicroWorld-eScanTrojan.GenericKD.43893131
TencentWin32.Trojan.Diztakun.Szla
Ad-AwareTrojan.GenericKD.43893131
SophosMal/Generic-S
ComodoMalware@#3fcbrs6pxskx3
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
FireEyeGeneric.mg.c4c22e78df660448
EmsisoftTrojan.GenericKD.43893131 (B)
AviraHEUR/AGEN.1116002
eGambitUnsafe.AI_Score_53%
MicrosoftTrojan:Win32/Dynamer!ac
ZoneAlarmTrojan.Win32.Diztakun.akln
GDataTrojan.GenericKD.43893131
Acronissuspicious
McAfeeArtemis!C4C22E78DF66
MAXmalware (ai score=82)
MalwarebytesMalware.AI.1783480604
PandaTrj/CI.A
YandexTrojan.DL.Dapato!zbx5/CkbPh0
IkarusTrojan.Win32.LockScreen
MaxSecureTrojan.Autoit.AZA
FortinetW32/LockScreen.BAJ!tr
AVGAutoIt:LockScreen-A [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.1783480604?

Malware.AI.1783480604 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment