Malware

Malware.AI.2041746974 information

Malware Removal

The Malware.AI.2041746974 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2041746974 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz
educationaltools.info

How to determine Malware.AI.2041746974?


File Info:

crc32: 751217AC
md5: a814bfb895f896aa01b43f4d5106d550
name: A814BFB895F896AA01B43F4D5106D550.mlw
sha1: 3ac95d0ffb3035a4eae25ce8dec05dd32fa6c9d2
sha256: 4772024a13ec600e10f7e3a9c6503b90a6ff917becd9197cc42d15c74da3acd0
sha512: 54283b5dee1c71af7846c9949dec0cdeff7a760bdaf2a412e54ea8067d1446c42ee3c64512a888eed5bae5d460a7c0cc79de6e43f268efe9191513e73cceeff2
ssdeep: 49152:yUTsamK2NUsbHToNoVduUsbHTokVTUsbHTokNh:yaz2NUkTeQcUkTxTUkTp
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

FileVersion: 1.3.3.7
Comments: 1hit
Translation: 0x0809 0x04b0

Malware.AI.2041746974 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 004d8c0a1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad4.11093
CynetMalicious (score: 100)
ALYacAIT:Trojan.Nymeria.402
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.41937
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.63cc5eeb
K7GWSpyware ( 004d8c0a1 )
Cybereasonmalicious.895f89
BaiduMulti.Threats.InArchive
CyrenW32/AutoIt.QV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Autoit-6961072-0
KasperskyTrojan-Ransom.Win32.Blocker.lkul
BitDefenderAIT:Trojan.GenericTKA.26
NANO-AntivirusTrojan.Win32.AutoIt.fkhysg
MicroWorld-eScanAIT:Trojan.GenericTKA.26
TencentWin32.Trojan.Blocker.Lkwy
Ad-AwareAIT:Trojan.GenericTKA.26
SophosMal/Generic-S
ComodoMalware@#3donhmz9tq2ay
BitDefenderThetaAI:Packer.DBCB5E9518
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DDL21
McAfee-GW-EditionBehavesLike.Win32.Spyware.tc
FireEyeGeneric.mg.a814bfb895f896aa
EmsisoftAIT:Trojan.GenericTKA.26 (B)
AviraTR/Spy.Autoit.oiyca
eGambitUnsafe.AI_Score_99%
MicrosoftPWS:AutoIt/Passup.A
AegisLabTrojan.Win32.Blocker.4!c
GDataAIT:Trojan.Nymeria.402 (5x)
AhnLab-V3Malware/Win32.Generic.C2837615
McAfeeArtemis!A814BFB895F8
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2041746974
TrendMicro-HouseCallTROJ_GEN.R002C0DDL21
RisingSpyware.AutoLOG/Autoit!1.C9CE (CLASSIC)
IkarusDropper.AutoIt
FortinetW32/AutoIt.CB!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.2041746974?

Malware.AI.2041746974 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment