Malware

Malware.AI.2140729432 removal guide

Malware Removal

The Malware.AI.2140729432 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2140729432 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits behavior characteristic of Nymaim malware
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
ywdovsevgsix.pw
svngj.in
ucuhdnk.com
kppxbflesjf.net
foqgqdqsr.net
invzip.net
vbcgkn.net
wpudukhqmg.in
wcspy.in
jdpurrjkzkgk.com
fzblwv.pw
omfqa.net
dprksr.net
wcqiaalh.in
dvyezqaxh.com
uqwnuyawxf.pw
knveaqucq.in
gihbokthvssn.com
txpgmqumzysx.pw
yfnaaejlgige.com
ofsivu.in
ercpzkehlby.in
yfmyfhmbxi.pw
dfgqvlpyks.net
faqhruraowd.net
dkgzjthjpoj.in
vzprpo.in
odcpduelqe.com
vnxnmvtzivn.in
qermqzwkab.in
srbuyaqocfu.in
kazif.com
cmcgim.pw
uwyqoplqrdt.net
zsjcrtwdhxop.com
bflqmbg.net
efbhycwgyj.in
fkhksduzospm.pw
tpkjg.in
qqlmujyg.net

How to determine Malware.AI.2140729432?


File Info:

crc32: A334D314
md5: 7f41955790f286278e3f31ff4346b3f3
name: 7F41955790F286278E3F31FF4346B3F3.mlw
sha1: 3f5e87a0aebc8458a704db99bc4e8333e34daca0
sha256: 18642613772b164c387f663bdc9e21d4aa9bddd65f117e8208e9a709b70197db
sha512: 4bc53276d1251aecdaef4c5b77128b52ac405a75718fa1f28f4fa2cc121319efe18f6112f2cd4cdab9c11ed8a32a0740d11129a9849506c3a67678c341f54279
ssdeep: 12288:3mDGIkrUdjqcD0v+/zHMS3sbjFZwolIWyNnOanVw5ITZ/p:3mDGIkriqy0vCHtsDwoV6VhNp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2140729432 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.59668
MicroWorld-eScanTrojan.Downloader.Nymaim.K
FireEyeGeneric.mg.7f41955790f28627
CAT-QuickHealTrojan.Refinka.YB5
McAfeeTrojan-FOEB!7F41955790F2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Refinka.4!c
SangforMalware
K7AntiVirusTrojan ( 005190011 )
BitDefenderTrojan.Downloader.Nymaim.K
K7GWTrojan ( 005176201 )
Cybereasonmalicious.790f28
BitDefenderThetaGen:NN.ZexaF.34804.MuW@a05PrNji
CyrenW32/S-6c263928!Eldorado
SymantecPacked.Generic.493
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Downloader.Nymaim-9779220-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.esvmtc
RisingTrojan.Kryptik!1.AE8F (CLOUD)
Ad-AwareTrojan.Downloader.Nymaim.K
EmsisoftTrojan.Downloader.Nymaim.K (B)
ComodoTrojWare.Win32.Ransom.Refinka.GL@794hgz
F-SecureHeuristic.HEUR/AGEN.1111249
ZillyaTrojan.Refinka.Win32.900
TrendMicroRansom_CERBER.SMALY0
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jc
SophosML/PE-A + Mal/Elenoocka-E
IkarusTrojan-Downloader.Win32.Nymaim
JiangminTrojan.Refinka.kc
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1111249
Antiy-AVLTrojan/Win32.Refinka
MicrosoftTrojanDownloader:Win32/Nymaim.K
ArcabitTrojan.Downloader.Nymaim.K
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Downloader.Nymaim.K
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Refinka.R209240
Acronissuspicious
VBA32Trojan.Refinka
ALYacTrojan.Downloader.Nymaim.K
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2140729432
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FWVM
TrendMicro-HouseCallRansom_CERBER.SMALY0
TencentMalware.Win32.Gencirc.10b4059d
YandexTrojan.GenAsa!VGSN0W0fWNI
SentinelOneStatic AI – Malicious PE – Downloader
eGambitUnsafe.AI_Score_63%
FortinetW32/Kryptik.GKKB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.6b0

How to remove Malware.AI.2140729432?

Malware.AI.2140729432 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment