Malware

What is “Malware.AI.2206971389”?

Malware Removal

The Malware.AI.2206971389 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2206971389 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2206971389?


File Info:

crc32: 6EDB44BD
md5: 1112204a4b687b43cc5aced620123397
name: 1112204A4B687B43CC5ACED620123397.mlw
sha1: 8f8a4015ea2d6c071c49680bd09a2ee2220e7fc5
sha256: 876a1a4a470855c51ea7f32ca24a5903078fb35e8e5d5da14be4db260625581c
sha512: 7d0986be3ffcb3b3bb51142f64f1426bad1c06d9b409bf1b8e73f5d6d0ef74a44719910edd54f9b41377c6354ff2ae97705e894528eead625ae634c61157ae73
ssdeep: 98304:TWJ8u1p9GHLObSw981QKxObGQa9QMICwkB0:TWeurQHSjkQKxObG1Qha0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2021
FileVersion: 1.0.1.325
CompanyName: x6ca7x5ddex5faex9177x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: ILoveImg.exe
ProductVersion: 1.0.1.325
FileDescription: ILoveImg.exe
OriginalFilename: ILoveImg.exe
Translation: 0x0804 0x04b0

Malware.AI.2206971389 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicAdware.Win32.MiniPages.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacApplication.Agent.JXF
CylanceUnsafe
ZillyaAdware.MiniPages.Win32.21
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaAdWare:Win32/AntZip.85d0296c
K7GWAdware ( 00589f0f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AntZip.A potentially unwanted
AvastWin32:AdwareX-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.MiniPages.gen
BitDefenderApplication.Agent.JXF
ViRobotAdware.Minipages.4540242
MicroWorld-eScanApplication.Agent.JXF
Ad-AwareApplication.Agent.JXF
SophosGeneric PUA IP (PUA)
BitDefenderThetaGen:NN.ZexaE.34294.@x2@a0uXFaij
TrendMicroTROJ_GEN.R03BC0PKE21
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeApplication.Agent.JXF
EmsisoftApplication.Agent.JXF (B)
JiangminAdWare.MiniPages.ap
AviraPUA/Agent.LS
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.34D273B
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitApplication.Agent.JXF
GDataApplication.Agent.JXF
AhnLab-V3Adware/Win.Minipage.C4530064
McAfeeGenericRXOK-RL!1112204A4B68
MAXmalware (ai score=74)
VBA32BScope.Adware.Softcnapp
MalwarebytesMalware.AI.2206971389
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0PKE21
RisingAdware.Agent!1.D0B9 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/AntZip
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.2206971389?

Malware.AI.2206971389 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment