Malware

Malware.AI.2678448597 removal tips

Malware Removal

The Malware.AI.2678448597 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2678448597 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2678448597?


File Info:

crc32: 27412BE3
md5: dde5e3410b076b8168baa4ad94d3bb93
name: DDE5E3410B076B8168BAA4AD94D3BB93.mlw
sha1: 56bf14eb9b39884825568d939ecf3505f5c0ef31
sha256: 11776f78d1e87398d54f9d45b62971f30af2466db9602a2ed6cccce72193a501
sha512: d96f715501e0d7ac2d3525864eb48bd00cb74e18a656ffae998506c14744cb55d3572640cedb886f78a6bc929b045eb0630dab8e7691a9c297c3b5cefaff8474
ssdeep: 24576:p59ofKMj9EhZfrHLyQ2rZtEV0fi/nGfnqwtLjQvYA5ZcFYEoxhwt:poCiEhxy3l0Gf7LjQcYXhe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.00.2900.2180
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Malware.AI.2678448597 also known as:

K7AntiVirusTrojan ( 0050c96f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebDDoS.MP.5
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5260901
ALYacMemScan:Trojan.Agent.CYIX
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Fynloski.56762cae
K7GWTrojan ( 0050c96f1 )
Cybereasonmalicious.10b076
CyrenW32/Injector.KNNU-9072
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Injector.DOIH
ZonerTrojan.Win32.55257
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Cyix-6914663-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderMemScan:Trojan.Agent.CYIX
NANO-AntivirusTrojan.Win32.Yakes.eodtwh
MicroWorld-eScanMemScan:Trojan.Agent.CYIX
TencentWin32.Trojan.Generic.Wwob
Ad-AwareMemScan:Trojan.Agent.CYIX
SophosMal/Generic-R
ComodoMalware@#rdqsmtornfu
BitDefenderThetaAI:Packer.7A611F3F23
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_FYNLOSKI.ABFN
McAfee-GW-EditionGenericR-JRO!42A8D107A36E
FireEyeGeneric.mg.dde5e3410b076b81
EmsisoftMemScan:Trojan.Agent.CYIX (B)
SentinelOneStatic AI – Suspicious SFX
JiangminTrojan.Yakes.uzc
AviraTR/Crypt.ZPACK.xejim
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.20027CD
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Fynloski.A
ArcabitTrojan.Agent.CYIX
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMemScan:Trojan.Agent.CYIX
McAfeeArtemis!DDE5E3410B07
MAXmalware (ai score=88)
VBA32Trojan.Yakes
MalwarebytesMalware.AI.2678448597
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_FYNLOSKI.ABFN
RisingTrojan.Injector!1.AFF6 (CLASSIC)
YandexTrojan.GenAsa!/B8ZMMSkYVs
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DOIH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.DarkKomet.HwYDEpsA

How to remove Malware.AI.2678448597?

Malware.AI.2678448597 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment