Malware

Malware.AI.2755220301 removal instruction

Malware Removal

The Malware.AI.2755220301 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2755220301 virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed analysis tools by a known file location
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Detects Sandboxie using a known mutex
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a device
  • Detects VMware through the presence of a registry key
  • Detects Virtual PC using a known mutex
  • Creates a copy of itself
  • Checks for a known DeepFreeze Frozen State Mutex
  • Collects information to fingerprint the system

How to determine Malware.AI.2755220301?


File Info:

crc32: 9A3A0E82
md5: 682081a5f90ac3189066bfc1f8fe75bf
name: 682081A5F90AC3189066BFC1F8FE75BF.mlw
sha1: a6b3879064497f355a9fcd66637e73834f2ab3e8
sha256: 998fe4896f8de56ff7941b522757e69c64f3a91742e3885c8af7d3c7f972b314
sha512: da263f1a5bfcd34d27649c59f120b14d01a90aa05e874cfb2af59dfbbc422766a92bba2456d1bafcf4ee3b52fbf081df8396017ea80eac0f1dc53df1e5072b3c
ssdeep: 3072:ase/r0ZuIfB1rN3PqCDLAWGbadfPSE2EdF1LzaJCx0s/l6KaKrV25pb:y0xti874Zq1LzgQzsb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2755220301 also known as:

K7AntiVirusSpyware ( 0055e3db1 )
LionicTrojan.Win32.Panda.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.11620
ClamAVWin.Malware.Panda-9814670-1
ALYacGen:Heur.Mint.Dreidel.hqW@xyZsH2m
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.197597
SangforTrojan.Win32.XPACK.Gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Panda.5ead566d
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.5f90ac
CyrenW32/Zbot.GMKH-1148
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Zbot.ACM
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Panda.i
BitDefenderGen:Heur.Mint.Dreidel.hqW@xyZsH2m
NANO-AntivirusTrojan.Win32.Panda.eyfatt
ViRobotTrojan.Win32.Z.Zbot.124416
MicroWorld-eScanGen:Heur.Mint.Dreidel.hqW@xyZsH2m
TencentWin32.Trojan-spy.Panda.Wnme
Ad-AwareGen:Heur.Mint.Dreidel.hqW@xyZsH2m
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.hqW@ayZsH2m
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT_GA250A22.UVPM
McAfee-GW-EditionPWSZbot-FASJ!682081A5F90A
FireEyeGeneric.mg.682081a5f90ac318
EmsisoftGen:Heur.Mint.Dreidel.hqW@xyZsH2m (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.19A9F89
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataGen:Heur.Mint.Dreidel.hqW@xyZsH2m
TACHYONTrojan-Spy/W32.Panda.124416
AhnLab-V3Trojan/Win32.Zbot.C3536248
Acronissuspicious
McAfeePWSZbot-FASJ!682081A5F90A
MAXmalware (ai score=87)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesMalware.AI.2755220301
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_ZBOT_GA250A22.UVPM
RisingRansom.Satan!1.AEB7 (CLASSIC)
YandexTrojan.GenAsa!JdsgkbgKHUQ
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.35EFC9!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2755220301?

Malware.AI.2755220301 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment