Malware

Malware.AI.2231889366 removal

Malware Removal

The Malware.AI.2231889366 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2231889366 virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Created a service that was not started

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2231889366?


File Info:

crc32: AA5B3302
md5: 5e6b6dda58832d556dd26a9078ed1c77
name: 5E6B6DDA58832D556DD26A9078ED1C77.mlw
sha1: ba77b1ee86f7ccd5eba86af30951e714e7fa50de
sha256: 23834d9de19a89427c3bc7c6b3c6beb2eece9dffc41444285884e6ee3836f176
sha512: a0fc5403de0af769b9e3ffb33b841376910f2e51158f12077a91fc3a3fff4d3c0f4874bd17dcb4bba0ab055911ea740b626c23de8ef2591843c21c7c02d4180b
ssdeep: 768:SAHYjqn/Ch3fYtPXEKoLG9EIK1aDD0yz9PkMpEIifI4IXyuQNTPkn:p0hQpXEKt9ytg9PmpmyuQNT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2231889366 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 0017e02e1 )
LionicTrojan.Win32.Geral.a!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop1.19539
CynetMalicious (score: 100)
ALYacTrojan.Downloader.Agent.ZAW
CylanceUnsafe
ZillyaDownloader.Geral.Win32.12489
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Geral.e5e845e9
K7GWTrojan-Downloader ( 0017e02e1 )
Cybereasonmalicious.a58832
BaiduWin32.Worm.AutoRun.ib
CyrenW32/Agent.FO.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/AntiAV.NEV
APEXMalicious
AvastWin32:Agent-AEVX [Trj]
ClamAVWin.Trojan.Rootkit-3084
KasperskyTrojan-Downloader.Win32.Geral.vnk
BitDefenderTrojan.Downloader.Agent.ZAW
NANO-AntivirusTrojan.Win32.Geral.czopk
ViRobotTrojan.Win32.Downloader.48640.CR
MicroWorld-eScanTrojan.Downloader.Agent.ZAW
TencentTrojan.Win32.Geral.vnk
Ad-AwareTrojan.Downloader.Agent.ZAW
SophosML/PE-A
ComodoTrojWare.Win32.TrojanDownloader.Geral.~vnk@2ma5vd
BitDefenderThetaAI:Packer.75BC7D291C
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
TrendMicroTROJ_KILLAV.SMEC
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ph
FireEyeGeneric.mg.5e6b6dda58832d55
EmsisoftTrojan.Downloader.Agent.ZAW (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Geral.auj
AviraTR/Killav.gox
Antiy-AVLTrojan/Generic.ASMalwS.1D441
MicrosoftTrojan:Win32/Killav
SUPERAntiSpywareTrojan.Agent/Gen-DelFile
GDataTrojan.Downloader.Agent.ZAW
TACHYONTrojan-Downloader/W32.Geral.48640
AhnLab-V3Trojan/Win32.Geral.R5411
Acronissuspicious
McAfeeGenericR-HRP!5E6B6DDA5883
MAXmalware (ai score=100)
VBA32Backdoor.Lareg
MalwarebytesMalware.AI.2231889366
PandaTrj/KillAV.LO
TrendMicro-HouseCallTROJ_KILLAV.SMEC
RisingTrojan.Generic@ML.99 (RDMK:EE4HMhGGoZJn81QZFaew/A)
YandexTrojan.GenAsa!NVAkwl4y8dE
IkarusTrojan-Downloader.Win32.Geral
MaxSecureTrojan.Malware.1499524.susgen
FortinetW32/Geral.VNK!tr
AVGWin32:Agent-AEVX [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2231889366?

Malware.AI.2231889366 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment