Malware

Malware.AI.2652521806 removal guide

Malware Removal

The Malware.AI.2652521806 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2652521806 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Yemen)
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2652521806?


File Info:

crc32: 03CF3A46
md5: 3a14447d7f4cd9be57240b7b524ce411
name: 3A14447D7F4CD9BE57240B7B524CE411.mlw
sha1: cbb550ac7d00cc2b14fbba474a44037b971157f9
sha256: 2609f9478d67a9873e072356c53509b22e05d3fb4831ce2e08f21e855d1204ab
sha512: 78b2821fa3f806a3d5e90b2331939cd59aa7dc007c513f39246e644d7a58ce482dd782f1f488bf75d579d306599997b461ffac0343016d2709b07ee68e2a8ef2
ssdeep: 12288:OzU/xOh53FP5Pk1HY53sHgQ+MXaPp3ekZ9qctc9ENpJCW9hPx9Q/hlpGJYh:7IlTk1HHHgQVXaB3ekjoENvCohPEhlp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 7, 22
FileVersion: 3, 3, 7, 22
FileDescription:
Translation: 0x0809 0x04b0

Malware.AI.2652521806 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.88505
FireEyeGeneric.mg.3a14447d7f4cd9be
ALYacGen:Variant.Barys.88505
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Variant.Barys.88505
K7GWTrojan ( 700000111 )
Cybereasonmalicious.d7f4cd
BitDefenderThetaAI:Packer.4ED90C6E19
CyrenW32/Trojan.UWKM-2330
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.Autoit.DAA
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Wecod.pht
AlibabaWorm:Win32/Wecod.2affd156
NANO-AntivirusTrojan.Win32.Wecod.crjkoj
AegisLabTrojan.Win32.Wecod.4!c
AvastAutoIt:Agent-K [Trj]
RisingTrojan.Generic@ML.98 (RDMK:dTln9uyxCTxhhvIeHQLQBg)
Ad-AwareGen:Variant.Barys.88505
EmsisoftGen:Variant.Barys.88505 (B)
ComodoMalware@#2qbwuodguwaz8
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen4.38188
ZillyaTrojan.Wecod.Win32.66
TrendMicroTROJ_SPNV.01D414
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Wecod.xk
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
KingsoftWin32.Troj.Wecod.p.(kcloud)
MicrosoftTrojanDownloader:Win32/Banload.AOU
ArcabitTrojan.Barys.D159B9
ZoneAlarmTrojan.Win32.Wecod.pht
GDataGen:Variant.Barys.88505
CynetMalicious (score: 100)
McAfeeArtemis!3A14447D7F4C
MalwarebytesMalware.AI.2652521806
TrendMicro-HouseCallTROJ_SPNV.01D414
TencentWin32.Trojan.Wecod.vzw
IkarusTrojan.Win32.Wecod
MaxSecureTrojan.Autoit.AZA
AVGAutoIt:Agent-K [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/Malware.QVM10.Gen

How to remove Malware.AI.2652521806?

Malware.AI.2652521806 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment