Malware

Malware.AI.2699678369 information

Malware Removal

The Malware.AI.2699678369 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2699678369 virus can do?

  • Attempts to connect to a dead IP:Port (14 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.baidu.com
client.5054399.com
b.533y.com
web.4399.com
pic.my4399.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
webpic.my4399.com
s19.cnzz.com
z8.cnzz.com
c.cnzz.com
ocsp.digicert.com
statuse.digitalcertvalidation.com
cnzz.mmstat.com
pcookie.cnzz.com

How to determine Malware.AI.2699678369?


File Info:

crc32: 5EC034AC
md5: 6b320f14fce82d600f207d7bc6a46cbd
name: 6B320F14FCE82D600F207D7BC6A46CBD.mlw
sha1: c1ae79e3d74e90ed6dd7c8b8837e117e37ee29ba
sha256: dbf1001a6502e4f5c8a6f0505683ad396462589f17f1e969b3a92d95843d829f
sha512: 91d3bfb83f2e559b1497ed1c61a48cf93f1f1486bf42cdf9d4b12597cdd9d19b7647579ebc8b815fe7f189b86a49b87ebbbb6c473e7602472adcaae4be1d4fd4
ssdeep: 12288:BPzTp6eXc5QHYWZc/OstA/I13YPLF41xolwQZN2ArmBQs:BPzTpE5QHYCVwCnLF41ilZZhiBQs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x56dbx4e09x4e5dx4e5dx7f51x7edcx80a1x4efdx6709x9650x516cx53f8 x4fddx7559x6240x6709x6743x5229x3002
InternalName: Cq69676.exe
FileVersion: cqms-qpb3-zddl
CompanyName: x56dbx4e09x4e5dx4e5dx7f51x7edcx80a1x4efdx6709x9650x516cx53f8
ProductName: 4399x523ax79e6x79d8x53f2
ProductVersion: cqms-qpb3-zddl
FileDescription: 4399x523ax79e6x79d8x53f2
OriginalFilename: Cq69676.exe
Translation: 0x0804 0x03a8

Malware.AI.2699678369 also known as:

K7AntiVirusUnwanted-Program ( 0054181a1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaDownloader:Win32/XPACK.07651d25
K7GWUnwanted-Program ( 0054181a1 )
Cybereasonmalicious.4fce82
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameTool.FL potentially unsafe
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
NANO-AntivirusTrojan.Win32.Razy.exalnl
TencentMalware.Win32.Gencirc.10b7072e
SophosGeneric PUA MB (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.Ru1@aCaJ@Gnj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGeneric-FAGI!6B320F14FCE8
FireEyeGeneric.mg.6b320f14fce82d60
SentinelOneStatic AI – Malicious PE
JiangminDownloader.Generic.aqxp
AviraTR/Patched.Gen
Antiy-AVLTrojan/Generic.ASMalwS.245FC32
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.RL_Generic.R278330
McAfeeGeneric-FAGI!6B320F14FCE8
MAXmalware (ai score=97)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.2699678369
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PIT21
RisingTrojan.Generic@ML.100 (RDML:WmU5SoiLdsPDXIguGDq87A)
YandexTrojan.GenAsa!IjnaRrMidfQ
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2699678369?

Malware.AI.2699678369 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment