Malware

How to remove “Malware.AI.1994761923”?

Malware Removal

The Malware.AI.1994761923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1994761923 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates Zeus (Banking Trojan) mutexes
  • Zeus P2P (Banking Trojan)
  • Attempts to modify browser security settings
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
bspsarea4a.co.uk

How to determine Malware.AI.1994761923?


File Info:

crc32: 68A2947A
md5: b6fd10d6a2c63debef8e2020590c18c1
name: B6FD10D6A2C63DEBEF8E2020590C18C1.mlw
sha1: 1a7428586bf4a2b628a1d3038234ee4697240b97
sha256: 1e0cfd648042c1e3cb7c96a6bcf5900a8c267ca31786489e171b8f1c8d289d25
sha512: 098f480a9c0a2565b8a9315835f9ae8fbce7cf0b5bcfafb3f2ffe5e0777802b1ab80abf61ce7a14c495a995f1e29c05a5074def7dfd9485fd56610ce4a204c54
ssdeep: 12288:N9YfhUgNdUAs6Fc76Uq0R0qRJVLhqtzsMTJVY08cK7fuBet+h06RUeU:NtC06RUb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: IbYwTj
FileVersion: 5.07.0005
CompanyName: Kjqb
LegalTrademarks: TssU
ProductName: eedh
ProductVersion: 5.07.0005
OriginalFilename: IbYwTj.exe

Malware.AI.1994761923 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3db1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2233
CynetMalicious (score: 100)
ALYacGen:Variant.Johnnie.297062
CylanceUnsafe
ZillyaTrojan.Spy.Win32.1589
SangforSpyware.Win32.Zbot.8
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Injector.c30f7532
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.6a2c63
CyrenW32/VBKrypt.CU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.QJG
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Zbot-6933952-0
KasperskyTrojan-Spy.Win32.Zbot.wont
BitDefenderGen:Variant.Johnnie.297062
NANO-AntivirusTrojan.Win32.Panda.ecjmqg
MicroWorld-eScanGen:Variant.Johnnie.297062
TencentMalware.Win32.Gencirc.114c05fd
Ad-AwareGen:Variant.Johnnie.297062
SophosMal/Generic-S
ComodoMalware@#1scj30xn35p9d
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot.gen.oj
FireEyeGeneric.mg.b6fd10d6a2c63deb
EmsisoftGen:Variant.Johnnie.297062 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Injector.aqxc
AviraTR/Dropper.VB.Gen
eGambitGeneric.Dropper
Antiy-AVLTrojan/Generic.ASMalwS.189FEF6
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/VBInject.gen!IY
GDataGen:Variant.Johnnie.297062
McAfeePWS-Zbot.gen.oj
MAXmalware (ai score=100)
VBA32BScope.TrojanBanker.Agent
MalwarebytesMalware.AI.1994761923
PandaTrj/GdSda.A
YandexTrojan.GenAsa!Pxopifb7vGc
IkarusPacked.Win32.Katusha
FortinetW32/VB.IKK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1994761923?

Malware.AI.1994761923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment