Malware

Malware.AI.2545744881 information

Malware Removal

The Malware.AI.2545744881 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Malware.AI.2545744881 virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Enumerates services, possibly for anti-virtualization
  • Mimics the file times of a Windows system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Malware.AI.2545744881?


File Info:

crc32: 43946D06
md5: bb7550cdfa8edbcf73e1a0d31c3da67d
name: BB7550CDFA8EDBCF73E1A0D31C3DA67D.mlw
sha1: 7abdbb88fea67c1c070fb9509d65e580e1f32030
sha256: c3065d9499b7130ddb28eaeeafcedb364608bf952f56eda130e91a2ac40f3e4c
sha512: 4ff1f0f4d6112c1f96e05761b261916c811bcc4016830d194b107d4b3900eaeb337be91b18da6cbe43187fd862146e4131eda463e7863abb6db6b559039ca40b
ssdeep: 6144:WkddhuIkh5zXsUpAKEccccccccccccsCCp1fBpzhhh2KNZbBKKKrx9rNUwgT:WkddhBkfgUtBpBBpcKwJgT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709(C) 2020
InternalName: loader
FileVersion: 1, 0, 0, 1
CompanyName: yida
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: yida loader
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: loader
OriginalFilename: loader.dat
Translation: 0x0804 0x04b0

Malware.AI.2545744881 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader35.10669
ClamAVWin.Dropper.Gh0stRAT-9791100-0
McAfeeGenericRXLQ-UU!BB7550CDFA8E
CylanceUnsafe
ZillyaBackdoor.Farfli.Win32.10092
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.dfa8ed
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CJVZ
APEXMalicious
AvastWin32:FileinfectorX-gen [Trj]
CynetMalicious (score: 99)
KasperskyHEUR:Backdoor.Win32.Farfli.gen
BitDefenderGen:Variant.Doina.8190
NANO-AntivirusTrojan.Win32.Farfli.ibdmwi
MicroWorld-eScanGen:Variant.Doina.8190
Ad-AwareGen:Variant.Doina.8190
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34170.Fq1@aSjZMakj
McAfee-GW-EditionGenericRXLQ-UU!BB7550CDFA8E
FireEyeGeneric.mg.bb7550cdfa8edbcf
EmsisoftGen:Variant.Doina.8190 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Farfli.edo
AviraHEUR/AGEN.1101568
Antiy-AVLTrojan/Generic.ASMalwS.30FC592
MicrosoftTrojan:Win32/Farfli.DSK!MTB
GridinsoftTrojan.Win32.Downloader.oa!s1
ArcabitTrojan.Doina.D1FFE
GDataWin32.Trojan.Farfli.VWWQP6
AhnLab-V3Malware/Win32.Generic.C4311411
VBA32BScope.Backdoor.Farfli
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2545744881
TrendMicro-HouseCallTROJ_GEN.R005C0DIS21
RisingTrojan.Kryptik!1.D32C (CLASSIC)
IkarusTrojan.Win32.Injector
FortinetW32/Farfli.BNZS!tr
AVGWin32:FileinfectorX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2545744881?

Malware.AI.2545744881 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment