Malware

Malware.AI.2555060608 (file analysis)

Malware Removal

The Malware.AI.2555060608 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2555060608 virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2555060608?


File Info:

crc32: D4B35E25
md5: ac2c41c0ed67949756f56c2211fdd8eb
name: AC2C41C0ED67949756F56C2211FDD8EB.mlw
sha1: 7c8349eb0070159582d4502f5adfa17cd0742676
sha256: eaa77cc3096898dd4802eafb0c3e8bf32f38e307ae1a3b00b65919be716b3c43
sha512: 3e6e9b8ebb1029369aba387b67b229697d7b7b05443817e0fec737894d5294bcf7e0342ab7aafe7191e70856158db012a40f81907f11207ab4c4db5c81680e2b
ssdeep: 1536:SetGSYjOagguj+HiKWZjXjf2wbkrexSu7jqwWi3IxbhJyh/:SeMS0a+XW5BbSQ4xb
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.2555060608 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Zusy.Elzob.1161
FireEyeGeneric.mg.ac2c41c0ed679497
McAfeeArtemis!AC2C41C0ED67
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Zusy.Elzob.1161
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
SymantecBackdoor.Trojan
TotalDefenseWin32/SillyDl.YVQ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Downloader.Win32.Agent.urrm
AlibabaTrojanDownloader:Win32/Banload.4171ad6b
NANO-AntivirusTrojan.Win32.Dorifel.cyoyte
ViRobotTrojan.Win32.Z.Zusy.80384.AJLC
Ad-AwareGen:Variant.Zusy.Elzob.1161
SophosMal/Generic-S
ComodoMalware@#1hu7nfdn03j5j
DrWebTrojan.Winlock.5631
ZillyaDownloader.Agent.Win32.424074
TrendMicroTROJ_BANLOAD.NT
McAfee-GW-EditionBehavesLike.Win32.Dropper.lc
EmsisoftGen:Variant.Zusy.Elzob.1161 (B)
IkarusTrojan.ATRAPS
JiangminTrojanDownloader.Delf.adxa
WebrootW32.Downloader.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Dropper]/Win32.Dorifel
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftTrojan:Win32/Sisproc
ArcabitTrojan.Zusy.Elzob.D489
ZoneAlarmTrojan-Downloader.Win32.Agent.urrm
GDataGen:Variant.Zusy.Elzob.1161
CynetMalicious (score: 100)
VBA32TrojanDownloader.Agent
ALYacGen:Variant.Zusy.Elzob.1161
MalwarebytesMalware.AI.2555060608
PandaGeneric Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.QUQ
TrendMicro-HouseCallTROJ_BANLOAD.NT
TencentWin32.Trojan-downloader.Agent.Lmum
YandexTrojan.DL.Agent!NBN8+OZ7+iQ
FortinetW32/Downloader_x.G2O!tr
BitDefenderThetaGen:NN.ZelphiF.34804.emGfayGBASiG
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360HEUR/Malware.QVM11.Gen

How to remove Malware.AI.2555060608?

Malware.AI.2555060608 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment