Malware

Malware.AI.1928725719 malicious file

Malware Removal

The Malware.AI.1928725719 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1928725719 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Unusual version info supplied for binary
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Malware.AI.1928725719?


File Info:

crc32: EFCD9FB6
md5: b5f727d196a740680acd3acbe4c6deff
name: B5F727D196A740680ACD3ACBE4C6DEFF.mlw
sha1: 071bcfccde5ae6832b34240e3634e93e48ca726d
sha256: a74253c90b1284734182797d9a75bd2defd94bed95022f50e44032bac22f3895
sha512: 63225709aef347cee14d9eb27f7d4cad790f33b2ae0fb52c99cf847218efa01b9bdcbfe25c6c0933f0b68bb47852e8b716d8efa1056642ffab58e8fccb23a2fa
ssdeep: 6144:KiupVPkKozcNoIcCn2TfHu5n3aMP99hl:2zP802onKe99
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2006 Microsoft Corporation. All rights reserved.
InternalName: dwtrig20.exe
FileVersion: 12.0.6606.1000
CompanyName: Mi crosoft Corporation
LegalTrademarks1: Microsoftxae is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windowsxae is a registered trademark of Microsoft Corporation.
ProductName: Watson Subscriber for SENS Network Notifications
ProductVersion: 12.0.6606.1000
FileDescription: Watson Subscriber for SENS Network Notifications
OriginalFilename: dwtrig20.exe
Translation: 0x0000 0x04e4

Malware.AI.1928725719 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.18445
CAT-QuickHealTrojanRansom.Crowti.MUE.A4
McAfeePWSZbot-FARM!B5F727D196A7
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005224381 )
Cybereasonmalicious.196a74
BaiduWin32.Trojan.Filecoder.q
CyrenW32/Cerber.D2.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.EXON
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Encoder.evpynr
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Crypt.Phzz
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Ransom-EJ
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
BitDefenderThetaGen:NN.ZexaF.34686.qq0@aGPunfni
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SMFD
McAfee-GW-EditionPWSZbot-FARM!B5F727D196A7
FireEyeGeneric.mg.b5f727d196a74068
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Trojan/Win32.RansomCrypt.R209670
Acronissuspicious
VBA32BScope.Trojan.Encoder
MAXmalware (ai score=99)
MalwarebytesMalware.AI.1928725719
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.SMFD
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazoHpYtvEk+vuBkYaynmUAT0)
IkarusTrojan.Win32.PSW
FortinetW32/Kryptik.FSUS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1928725719?

Malware.AI.1928725719 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment