Malware

Malware.AI.2686214264 removal instruction

Malware Removal

The Malware.AI.2686214264 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2686214264 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2686214264?


File Info:

crc32: B81F1607
md5: c4498b358aca193ec4210fac7341f9b7
name: C4498B358ACA193EC4210FAC7341F9B7.mlw
sha1: 0fc203337e5899d320c84854c9e76f38bff07c7c
sha256: 8ef89273bb0508d4c300707395766d33178661f61d812a536e7c652b69c42f8f
sha512: fab8f6ec811e270e695b29d38fb0e0bd6b2bd143d2e317477a070fd80195b20bbd2e42d47a3b26bbd29d53f5273d4b13a14b6cff3bb5cd0c5f13ba8b23cd455f
ssdeep: 384:lPiMVBIV2mDmqOs3zrcerMomlAtO4nA/ckZnyXFd2k99Tkk0lE3+HtmRroqd:lP1mVZLzAmOxkMn0FV9o7lEQmJok
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2686214264 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 000f60651 )
Elasticmalicious (high confidence)
DrWebWin32.HLLP.Nemesis.28687
CynetMalicious (score: 99)
ALYacGen:Variant.Doina.11608
CylanceUnsafe
ZillyaTrojan.Prisos.Win32.7
K7GWTrojan ( 000f60651 )
Cybereasonmalicious.58aca1
BaiduWin32.Backdoor.Prisos.b
CyrenW32/TianYan.A.gen!Eldorado
SymantecW32.Killaut.A
ESET-NOD32Win32/Prisos.A
AvastWin32:Dropper-FJM [Drp]
KasperskyTrojan.Win32.Agent.netfau
BitDefenderGen:Variant.Doina.11608
NANO-AntivirusTrojan.Win32.TianYan.cqjjhu
MicroWorld-eScanGen:Variant.Doina.11608
TencentWin32.Trojan.Agent.Swkn
Ad-AwareGen:Variant.Doina.11608
ComodoTrojWare.Win32.TrojanSpy.TianYan.~A@1qz4h
BitDefenderThetaGen:NN.ZexaCO.34266.cqW@a4sgpJaO
VIPREBackdoor.Win32.Prisos.A (v)
TrendMicroTSPY_TIANYAN.SMD
McAfee-GW-EditionBackDoor-YA.a
FireEyeGeneric.mg.c4498b358aca193e
EmsisoftGen:Variant.Doina.11608 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.TianYan.a
AviraTR/Spy.Genome.rlce
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.AE45
KingsoftHeur.SSC.2622419.1216.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AB8E
GDataGen:Variant.Doina.11608
McAfeeBackDoor-YA.a
MAXmalware (ai score=99)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesMalware.AI.2686214264
PandaTrj/Agent.ICU
TrendMicro-HouseCallTSPY_TIANYAN.SMD
RisingTrojan.Spy.Win32.TianYan.a (CLASSIC)
YandexTrojan.GenAsa!n6UC/oRCe/I
IkarusTrojan-Spy.Win32.TianYan.b
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Prisos.A!tr
AVGWin32:Dropper-FJM [Drp]
Paloaltogeneric.ml

How to remove Malware.AI.2686214264?

Malware.AI.2686214264 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment