Malware

Malware.AI.2638951949 removal guide

Malware Removal

The Malware.AI.2638951949 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2638951949 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2638951949?


File Info:

crc32: 2FC10621
md5: affe5ce6621c2fc80d31346b7408a5ff
name: AFFE5CE6621C2FC80D31346B7408A5FF.mlw
sha1: a895b566ee43e7150c8fdddc4e174bcc6ec725ec
sha256: 9e338b6186665c4133a54311cffeae1958a2e9d0fde34f3a2cbc47023c5d8d57
sha512: 9221d2f610f144f4aed66abaf4a23cbd215fe7c9f50977567c37b5f8418959458ad0b7cd314b4421b11e062ad009ad666f18be61cd3e31a3715003aa4bfbf51e
ssdeep: 1536:R1FbuCjwkEK4/1xGC6RiNUkcp6A0N+h3CHnIEZ4CAq68dE:RPP0/bGC0D7qnIUAqJO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Run.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Run
ProductVersion: 1.0.0.0
FileDescription: Run
OriginalFilename: Run.exe

Malware.AI.2638951949 also known as:

K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 99)
CAT-QuickHealTrojanRansom.MSIL
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaDropper.Encoder.Win32.7
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:MSIL/Filecoder.95153204
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6621c2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.NC
APEXMalicious
AvastWin32:Agent-AZUV [Trj]
KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.gen
BitDefenderGen:Variant.Razy.769547
NANO-AntivirusTrojan.Win32.Ransom.fkgnbd
ViRobotTrojan.Win32.S.Agent.120832.HT
MicroWorld-eScanGen:Variant.Razy.769547
TencentMsil.Trojan.Encoder.Lswc
Ad-AwareGen:Variant.Razy.769547
SophosMal/Generic-S
ComodoMalware@#2olbq7nn2jcys
BitDefenderThetaGen:NN.ZemsilF.34690.hm0@aqcbKeh
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Encoder.R002C0GEI21
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Razy.769547
EmsisoftGen:Variant.Razy.769547 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.MSIL.knup
AviraTR/Dropper.MSIL.Gen
MicrosoftRansom:Win32/Genasom
AegisLabTrojan.MSIL.Encoder.4!c
GDataGen:Variant.Razy.769547
AhnLab-V3Trojan/Win32.Genasom.C2814392
McAfeeArtemis!AFFE5CE6621C
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.2638951949
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Encoder.R002C0GEI21
RisingRansom.Destructor!1.B060 (CLOUD)
YandexTrojan.Filecoder!IJfiPs5YY6I
IkarusTrojan.Dropper
FortinetMSIL/Filecoder.NC!tr.ransom
AVGWin32:Agent-AZUV [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2638951949?

Malware.AI.2638951949 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment