Malware

How to remove “Malware.AI.2730188524”?

Malware Removal

The Malware.AI.2730188524 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2730188524 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2730188524?


File Info:

crc32: 5A022EF9
md5: 47472e036c6afd95179fcc468e3a93bd
name: 47472E036C6AFD95179FCC468E3A93BD.mlw
sha1: 43b36b8a1b341954545d2faca37211972d2881f1
sha256: a97de27b0f7ad4c5393b3e36533924e064201723630438652ce0f1e3ef1eaa81
sha512: 1ef330e678b5c53bb05133c118d8324bfec55f4d327875c14ea1d98aaed27b77fa981b1f144f7da78bf1b49d85a876e348cb3d11e199d8a145e3cfc875816802
ssdeep: 1536:R0XJ6HXcylHqVKLIAP2QcL+4GjyB6t6d9Zeyf9OHmwt:R0AHXcyZcKLIAP2Qc7MyBrd9cyfbwt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2730188524 also known as:

K7AntiVirusTrojan ( 004f84891 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.6203
ALYacGeneric.Ransom.Unlock92.1CD14CF9
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.726
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:MSIL/Filecoder.3b6ddd57
K7GWTrojan ( 004f84891 )
Cybereasonmalicious.36c6af
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.CL
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.Ransom.Unlock92.1CD14CF9
NANO-AntivirusTrojan.Win32.Encoder.egohgf
MicroWorld-eScanGeneric.Ransom.Unlock92.1CD14CF9
TencentMsil.Trojan.Geograph.Pbzb
Ad-AwareGeneric.Ransom.Unlock92.1CD14CF9
SophosMal/Generic-S
ComodoMalware@#24o30wom8d2ta
BitDefenderThetaGen:NN.ZemsilF.34142.fqW@ayyCdBak
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R034E02CB17
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
FireEyeGeneric.mg.47472e036c6afd95
EmsisoftGeneric.Ransom.Unlock92.1CD14CF9 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.dzie
AviraHEUR/AGEN.1116609
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.1B7CEDD
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitGeneric.Ransom.Unlock92.1CD14CF9
GDataMSIL.Trojan-Ransom.Unlock92.C
McAfeeGeneric.akb
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.2730188524
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R034E02CB17
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Filecoder.CL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2730188524?

Malware.AI.2730188524 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment