Malware

Malware.AI.2502773800 removal

Malware Removal

The Malware.AI.2502773800 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2502773800 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of iSpy Keylogger
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2502773800?


File Info:

crc32: 85FFA26B
md5: bca7a06b0d1abb046b763433f1aa5d6d
name: BCA7A06B0D1ABB046B763433F1AA5D6D.mlw
sha1: 24090127913b26ad6f4dfdb1b7b76330ce82fb9a
sha256: d319b8258f9393459437d8360bba40fa0e013ea0e53ede09b7f094313a89940a
sha512: 333eaf52aa3fd19711bbfcbe81cef7264fd4e91fea54d61a75d751c69b7441f8792eb316814d225cfc5b0ba36a9c3e46b2e247724fccfb7a15e6d2c3abbdcda6
ssdeep: 1536:hgdEJkS+3dTbiJECJf7oasUO2IBDW6L2W:hg6J6UJECJf7oasUki6SW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: test.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: test.exe

Malware.AI.2502773800 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.MSIL.Basic.3.Gen
FireEyeGeneric.mg.bca7a06b0d1abb04
CAT-QuickHealTrojan.MsilFC.S17873470
ALYacTrojan.MSIL.Basic.3.Gen
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053564e1 )
BitDefenderTrojan.MSIL.Basic.3.Gen
K7GWTrojan ( 0053564e1 )
CyrenW32/MSIL_Kryptik.BBT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Packed.Nanocore-9783367-1
KasperskyHEUR:Trojan.MSIL.Dnoper.gen
Ad-AwareTrojan.MSIL.Basic.3.Gen
EmsisoftTrojan.MSIL.Basic.3.Gen (B)
F-SecureHeuristic.HEUR/AGEN.1100481
DrWebTrojan.Inject3.17989
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
SophosMal/Generic-S
AviraHEUR/AGEN.1100481
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.MSIL.Basic.3.Gen
ZoneAlarmHEUR:Trojan.MSIL.Dnoper.gen
GDataTrojan.MSIL.Basic.3.Gen
CynetMalicious (score: 100)
McAfeeGenericRXHW-EA!BCA7A06B0D1A
MAXmalware (ai score=88)
MalwarebytesMalware.AI.2502773800
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.SDD
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.MEA!tr
BitDefenderThetaGen:NN.ZemsilF.34590.em0@aWynd8e
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.b0d1ab
Qihoo-360HEUR/QVM03.0.8B75.Malware.Gen

How to remove Malware.AI.2502773800?

Malware.AI.2502773800 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment