Malware

Malware.AI.2189502091 (file analysis)

Malware Removal

The Malware.AI.2189502091 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2189502091 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2189502091?


File Info:

crc32: 2DDC4467
md5: a419205d24c85a4bdf547b0c1c980418
name: A419205D24C85A4BDF547B0C1C980418.mlw
sha1: ae547e56b8933f1bd4f9137b8e7392ecade26900
sha256: 21243a6089caa3de4cf1d3e2bf7c0810ee2951cfced42d28e187652c146b1e2b
sha512: 74085eaacc828af053a01caa80a6288b368b3ae3f34b07604b7bed084da99812ba46cb8533f607366f52a0448cac3cfb4ce2fd5edfa55afdcdeb772bf9f492cd
ssdeep: 768:tOjfqapn/ATeAQDxiXV08ddREg8XFRGXD8e/buUl:Yn/AoPGX4ezd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 0.00
InternalName: hyjhyhyyyyyyyyyy
FileVersion: 0.00
OriginalFilename: hyjhyhyyyyyyyyyy.exe
ProductName: stub

Malware.AI.2189502091 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004c12151 )
LionicTrojan.Win32.VB.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.215907
CylanceUnsafe
ZillyaDropper.VB.Win32.71137
AlibabaTrojanDropper:Win32/Injector.6f5c765c
K7GWTrojan ( 004c12151 )
Cybereasonmalicious.d24c85
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CNML
AvastWin32:VBCrypt-DCI [Trj]
ClamAVWin.Dropper.Johnnie-9797592-0
KasperskyTrojan-Dropper.Win32.VB.dtfg
BitDefenderGen:Variant.Bulz.215907
NANO-AntivirusTrojan.Win32.VB.fkoxbv
MicroWorld-eScanGen:Variant.Bulz.215907
TencentWin32.Trojan-dropper.Vb.Ljjt
Ad-AwareGen:Variant.Bulz.215907
SophosML/PE-A
ComodoMalware@#kz3jvxwihf1s
BitDefenderThetaAI:Packer.CB4C677720
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.pt
FireEyeGeneric.mg.a419205d24c85a4b
EmsisoftGen:Variant.Bulz.215907 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.VB.avhk
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2993A16
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Bulz.215907
AhnLab-V3Trojan/Win32.Injector.C2862543
McAfeeArtemis!A419205D24C8
MAXmalware (ai score=100)
VBA32Malware-Cryptor.VB.gen.1
MalwarebytesMalware.AI.2189502091
PandaTrj/GdSda.A
YandexTrojan.GenAsa!g3tGQj3mNu0
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.VQV!tr
AVGWin32:VBCrypt-DCI [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2189502091?

Malware.AI.2189502091 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment