Malware

Malware.AI.2463335479 removal guide

Malware Removal

The Malware.AI.2463335479 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2463335479 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Installs a browser addon or extension
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Attempts to modify browser security settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2463335479?


File Info:

crc32: 557D9E44
md5: 9c27c33e7cab9e19c33f8f00726b15f3
name: 9C27C33E7CAB9E19C33F8F00726B15F3.mlw
sha1: 34497b7af34611336d80e58bf2868da0c28ec02f
sha256: d70a77f92e5bb0bc6df6ff5fb3408bccbb0db9cb0188d0f6dd5c87b6ee7c74cd
sha512: 8b410f6202fc4a4defd03f5ed6b099022f43ff8cb64118c0cd9711a29060e5d83fc1f9b8dcb15e14999b860adb623881dde2ee6d1407d2bc3cb76c6ad58c9abe
ssdeep: 49152:m1SSgMam6Vkynv/RqH8EmRpQNDsavGoO1UG:m1SSvaxVkt87RpQ6XRT
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Skype
FileVersion: 1.0.0.0
CompanyName: Skype
Comments: Skype
ProductName: Skype
ProductVersion: 1.0.0.0
FileDescription: Skype
Translation: 0x0804 0x04b0

Malware.AI.2463335479 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 005070c51 )
LionicTrojan.Win32.Agent.m!c
Elasticmalicious (high confidence)
DrWebJS.DownLoader.5738
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46571377
CylanceUnsafe
AlibabaBackdoor:Win32/VBInject.1628bf1b
K7GWAdware ( 005070c51 )
Cybereasonmalicious.af3461
CyrenW32/Trojan.PZRL-0787
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Agent.myucid
BitDefenderTrojan.GenericKD.46571377
NANO-AntivirusTrojan.Win32.Farfli.ixdclv
MicroWorld-eScanTrojan.GenericKD.46571377
TencentWin32.Backdoor.Agent.Htvr
Ad-AwareTrojan.GenericKD.46571377
SophosGeneric PUA DE (PUA)
F-SecureBackdoor.BDS/Agent.yhigr
BitDefenderThetaGen:NN.ZexaF.34170.Lj0aaq3moOhb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PG621
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.9c27c33e7cab9e19
EmsisoftTrojan.GenericKD.46571377 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.aiote
AviraBDS/Agent.yhigr
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Generic.D2C69F71
ZoneAlarmBackdoor.Win32.Agent.myucid
GDataTrojan.GenericKD.46571377
AhnLab-V3Malware/Win.Generic.C4541068
McAfeeArtemis!9C27C33E7CAB
MAXmalware (ai score=81)
VBA32Backdoor.Agent
MalwarebytesMalware.AI.2463335479
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PG621
YandexBackdoor.Agent!SalSOrvTSno
IkarusVirus.Win32.VBInject
FortinetRiskware/Agent
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2463335479?

Malware.AI.2463335479 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment