Malware

Malware.AI.2380724246 removal

Malware Removal

The Malware.AI.2380724246 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2380724246 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2380724246?


File Info:

crc32: D5AC6BD0
md5: cdbaafc15dd9ad714363751a92611198
name: CDBAAFC15DD9AD714363751A92611198.mlw
sha1: b58d73f541d1b7174b5663dab1b5599a1f381b56
sha256: 5fc39fb6c46e3b4917914f8062fbad79c90ef0bba15088c99e40f7916ed12594
sha512: 81074b64d280d6bebd02893df28d3f01cb38cffff7381f4eefa1eea49fd7a9490ae73f7c8295f7ff144e49a8d236747580181fbfbab80402656aee84594690a1
ssdeep: 3072:BtnAwD4KlKgfgEYVGpBRMaaZ34vPMponvio+Qgx0rhKC0t3PBc7KHwKyL:Bik4KUfGU340rEgxhJPBUKLy
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: sample.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: sample.exe

Malware.AI.2380724246 also known as:

K7AntiVirusTrojan ( 005126fb1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.654732
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3624894
SangforTrojan.Win32.Generic.8
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Bulz.654732
K7GWTrojan ( 005126fb1 )
Cybereasonmalicious.541d1b
CyrenW32/Ransom.AY.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.KCB
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaBackdoor:MSIL/Kryptik.26bc24c8
NANO-AntivirusTrojan.Win32.AD.erfvsn
MicroWorld-eScanGen:Variant.Bulz.654732
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Bulz.654732
SophosMal/Generic-R + Mal/MSIL-TH
ComodoMalware@#3gfw98wfzq103
BitDefenderThetaGen:NN.ZemsilF.34294.pm0@aaoKX8b
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RKK21
FireEyeGeneric.mg.cdbaafc15dd9ad71
EmsisoftGen:Variant.Bulz.654732 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1122372
Antiy-AVLTrojan/Generic.ASMalwS.2703AA2
GDataGen:Variant.Bulz.654732
AhnLab-V3Trojan/Win32.Bladabindi.R149373
Acronissuspicious
MAXmalware (ai score=89)
MalwarebytesMalware.AI.2380724246
TrendMicro-HouseCallTROJ_GEN.R002C0RKK21
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.KCB!tr
PandaTrj/GdSda.A

How to remove Malware.AI.2380724246?

Malware.AI.2380724246 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment