Malware

Malware.AI.2265814954 removal guide

Malware Removal

The Malware.AI.2265814954 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2265814954 virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
2qaporw8r9km.9tntegmhdo.xyz

How to determine Malware.AI.2265814954?


File Info:

crc32: 2EB9E58E
md5: 3f295401fa59a32ff7a11551551ec607
name: 3F295401FA59A32FF7A11551551EC607.mlw
sha1: 2e1f1c03ee126297a64ea285c195f0864e91e824
sha256: 15a30214723fe2a98e86c6f542aa6c2394c73eab93d464fa75c4c833df7b8509
sha512: 555c2fd0247085d71cf14d780dc2f9e2d2119a1baabc3c0fbb3adf584a04e910a9b615a0995f98fb0dbfae6dc68e005ca8222787d775765cc86ee81c29e48a8c
ssdeep: 12288:bjV1vbtjwLBSbGS0wjraZU2FhujubNjcPdMVs7:bjHUSzj2ZU2Fhi6jKqG7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2021 x6d77x5357x7231x73a9x5b9dx7f51x7edcx79d1x6280x6709x9650x516cx53f8
InternalName: test.exe
FileVersion: 1.0.0.1
CompanyName: x6d77x5357x7231x73a9x5b9dx7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: test.exe
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: test.exe
Translation: 0x0804 0x04b0

Malware.AI.2265814954 also known as:

Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
MicroWorld-eScanGen:Variant.Johnnie.303898
FireEyeGeneric.mg.3f295401fa59a32f
CAT-QuickHealTrojan.Multi
McAfeeGenericRXNN-AN!3F295401FA59
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 005771151 )
BitDefenderGen:Variant.Johnnie.303898
K7GWTrojan-Downloader ( 005771151 )
Cybereasonmalicious.1fa59a
BitDefenderThetaAI:Packer.9BB6CAAB20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojanDownloader:Win32/DLOADER.823bd2aa
RisingTrojan.Hijacker!1.D0BA (CLOUD)
Ad-AwareGen:Variant.Johnnie.303898
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Agent.jrtbc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
EmsisoftGen:Variant.Johnnie.303898 (B)
IkarusTrojan-Downloader.Win32.Agent
AviraTR/Dldr.Agent.jrtbc
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Johnnie.D4A31A
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Johnnie.303898
CynetMalicious (score: 100)
ALYacGen:Variant.Johnnie.303898
MalwarebytesMalware.AI.2265814954
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FMH
TrendMicro-HouseCallTROJ_GEN.R06CH09AS21
TencentWin32.Trojan-downloader.Agent.Llhp
SentinelOneStatic AI – Suspicious PE – Adware
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.FMH!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.2265814954?

Malware.AI.2265814954 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment