Malware

Malware.AI.2121159026 (file analysis)

Malware Removal

The Malware.AI.2121159026 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2121159026 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

potiys.net
mopiiueus.com
louqwesas.com

How to determine Malware.AI.2121159026?


File Info:

crc32: A56C47D2
md5: 6988d55e62e4fd51d451583242dfb663
name: 6988D55E62E4FD51D451583242DFB663.mlw
sha1: c03ca8c590bab2214aab6eadefca4d11ab1e7e36
sha256: a65334191e9d29d423f85fa5c464b5dcbba08e5a48db3ac7a5dc52cd7857b90f
sha512: 979d59497a29576c840c558f8e17cb974e90fb9c5af37fda41abfafd1a96e09fb3669220270703664f4cbb85ccf63ed7806605465b6e492b5042624b5e4e35ac
ssdeep: 1536:GIHbnQJdvvI0xa4BxetcxAMes2ivBL86uemkSjBzpdeqHSM/KMSRUXQaoC:hHbQnXHetcxJ2iveeWBzpde6SSQaB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2121159026 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Butirat.60
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Vundo.Gen
ALYacGen:Variant.Zusy.10792
CylanceUnsafe
ZillyaTrojan.Agent.Win32.247501
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaVirTool:Win32/Injector.3afb7cbf
Cybereasonmalicious.e62e4f
CyrenW32/Zbot.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/SpyVoltar.A
APEXMalicious
AvastWin32:Buterat-NA [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.10792
NANO-AntivirusTrojan.Win32.Blocker.tsbmi
ViRobotTrojan.Win32.A.Blocker.126976.L
MicroWorld-eScanGen:Variant.Zusy.10792
TencentWin32.Trojan.Blocker.Wqdk
Ad-AwareGen:Variant.Zusy.10792
SophosML/PE-A + Mal/Vundo-AJ
ComodoTrojWare.Win32.Vundo.AZ@4pigkd
BitDefenderThetaGen:NN.ZexaF.34170.hqW@a8PbAgak
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.6988d55e62e4fd51
EmsisoftGen:Variant.Zusy.10792 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Agent.gbbm
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.4EF832
MicrosoftTrojan:Win32/Vundo.QA
GDataGen:Variant.Zusy.10792
AhnLab-V3Trojan/Win32.Gimemo.R27928
Acronissuspicious
McAfeeArtemis!6988D55E62E4
MAXmalware (ai score=100)
VBA32Hoax.Blocker
MalwarebytesMalware.AI.2121159026
PandaGeneric Malware
RisingTrojan.Generic@ML.99 (RDML:etCJPi22SBDsAfe10I74tg)
YandexTrojan.Blocker!HYx19Z4LVDQ
IkarusTrojan-Ransom.PornoAsset
MaxSecureTrojan.Malware.4199352.susgen
FortinetW32/SpyVoltar.A!tr
AVGWin32:Buterat-NA [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2121159026?

Malware.AI.2121159026 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment