Malware

Malware.AI.2219389603 (file analysis)

Malware Removal

The Malware.AI.2219389603 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2219389603 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Network activity contains more than one unique useragent.
  • Attempts to modify browser security settings

Related domains:

github.com
api.github.com

How to determine Malware.AI.2219389603?


File Info:

crc32: 85D144BA
md5: 4240d94dbd170abf148102f546ec430a
name: 4240D94DBD170ABF148102F546EC430A.mlw
sha1: 5d9459aa95bf3b1c34570369c324791630d917b1
sha256: 2add6e1e3b1a42cd4f667456a1fe60fca60e4ba73cc2e70a4dd9d3f7352dcd76
sha512: 668c07222a6d7797c4d6429f65e0601e611b3e4577533f7edd5f84155a723beeb7637cfb8f13d7ff962996e2b086514999a528f1ed523aff454b6b9c1dd2368b
ssdeep: 24576:zdLQ9el6mc+lZ62gEHY17I6RxHX5BusZ9PJs+y183:VsG6H6ioePJs+yo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020 CodISH inc.
InternalName: FET Loader
FileVersion: 2.2.9.1
CompanyName: CodISH Inc.
ProductName: FET Loader
ProductVersion: 2.2.9.1
FileDescription: A simple cheats loader written in AHK.
OriginalFilename:
Translation: 0x0409 0x04b0

Malware.AI.2219389603 also known as:

K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.35131869
CylanceUnsafe
ZillyaTrojan.APosT.Win32.1659
SangforTrojan.Win32.Ymacco.AA08
AlibabaTrojan:Win32/Generic.1ffe348c
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.dbd170
CyrenW32/Trojan.XSEF-5566
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Apost-9786630-0
BitDefenderTrojan.GenericKD.35131869
MicroWorld-eScanTrojan.GenericKD.35131869
TencentWin32.Trojan.Apost.Pabo
Ad-AwareTrojan.GenericKD.35131869
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.lhigr
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03BC0WKE20
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.4240d94dbd170abf
EmsisoftTrojan.GenericKD.35131869 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Taskun.u
AviraTR/Redcap.lhigr
MicrosoftTrojan:Win32/Ymacco.AA08
ArcabitTrojan.Generic.D21811DD
GDataTrojan.GenericKD.35131869
McAfeeArtemis!4240D94DBD17
MAXmalware (ai score=99)
VBA32BScope.Trojan.Banpak
MalwarebytesMalware.AI.2219389603
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0WKE20
RisingTrojan.Generic@ML.100 (RDML:yUJODVaWjBBd9J4sJSi0PA)
MaxSecureTrojan.Malware.11910789.susgen
FortinetW32/APosT!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.4a8

How to remove Malware.AI.2219389603?

Malware.AI.2219389603 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment