Malware

Malware.AI.2165167748 (file analysis)

Malware Removal

The Malware.AI.2165167748 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2165167748 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Created a service that was not started

How to determine Malware.AI.2165167748?


File Info:

crc32: 1515DB0D
md5: 1263c25f518a6654090dfd7607a9710a
name: 1263C25F518A6654090DFD7607A9710A.mlw
sha1: 91c10ebb5ce1d797578496adeb6f5afb105f439b
sha256: 4ffa66fa044ca27d4bc388f0c873ece4d93bed6bb0c9b296981c10a21dcc8b39
sha512: d56b9b4c8766d127f47d18489395c70f4c4d640da65568ac88d935a7e30fe25048c7a49ed0ef107ecff326850b73c7a3837ca97cc16c70ae97cdadf3abc6b3a4
ssdeep: 6144:bhY8qXXYBMgdub9pc5hN7/elG6SlJAAilXeyXNUEeDhRx4T+9RIz:qYBMOuxpcHFp6SQjXNXW/dRo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2165167748 also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop18.54150
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Rincux2.DAE81581
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.40312
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:Win32/Farfli.2dd48eca
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f518a6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FNMX
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Rincux-9880350-0
KasperskyHEUR:Backdoor.Win32.Farfli.gen
BitDefenderDeepScan:Generic.Rincux2.DAE81581
MicroWorld-eScanDeepScan:Generic.Rincux2.DAE81581
TencentWin32.Backdoor.Farfli.Dvzn
Ad-AwareDeepScan:Generic.Rincux2.DAE81581
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.XuX@aumiZGe
TrendMicroBackdoor.Win32.ZEGOST.SMAL02
McAfee-GW-EditionGenericRXQR-RV!1263C25F518A
FireEyeGeneric.mg.1263c25f518a6654
EmsisoftDeepScan:Generic.Rincux2.DAE81581 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Farfli.ertwb
Antiy-AVLTrojan/Generic.ASMalwS.34CA976
MicrosoftTrojan:Win32/Farfli.DSK!MTB
GDataDeepScan:Generic.Rincux2.DAE81581
AhnLab-V3Backdoor/Win.ZEGOST.C4766447
McAfeeGenericRXQR-RV!1263C25F518A
MAXmalware (ai score=86)
VBA32BScope.Backdoor.Farfli
MalwarebytesMalware.AI.2165167748
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMAL02
RisingTrojan.Kryptik!1.D241 (CLASSIC)
YandexTrojan.Agent!kpnXOA/68×4
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Backdoor_Win32_ZEGOST.SMAL02
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2165167748?

Malware.AI.2165167748 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment