Malware

About “Malware.AI.282495394” infection

Malware Removal

The Malware.AI.282495394 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.282495394 virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Malware.AI.282495394?


File Info:

crc32: B45EA5F1
md5: 7d7417e8d80536f12e51d76b81022a21
name: 7D7417E8D80536F12E51D76B81022A21.mlw
sha1: dc0f4135e8c69398d41a3ce10c587411a18f111b
sha256: 063b9758cb486835bf3d7593a5ffa4c304d1aab2f9cdab5d38403721ce8cd383
sha512: 5b81184cbf93ffc164b83a949e86905e87c38b2c623c15f8bd2ee05abd6557f74ff1cec702dece9adcdaced2f6859d378ffa93faf26dc778c8860ae19c96d863
ssdeep: 24576:i+8Oha/+adDwZYZ6pDSoHILUqSRftNoQWBghRwpzFF8A8X0oKXW:i+o2alk3HIohhtNWgqFkX0ow
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Malware.AI.282495394 also known as:

K7AntiVirusUnwanted-Program ( 004d38111 )
Elasticmalicious (high confidence)
DrWebTool.KMS.7
CynetMalicious (score: 100)
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.42202272
CylanceUnsafe
ZillyaAdware.Sahagent.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaHackTool:Win32/KMSAuto.8e41a12e
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.8d8053
CyrenW32/SecRisk-ProcessPatcher-Sml-
SymantecTrojan.Gen.X
ESET-NOD32a variant of Win32/StartPage.AOU
APEXMalicious
AvastWin32:Malware-gen
KasperskyHackTool.Win64.KMSAuto.b
BitDefenderTrojan.GenericKD.42202272
NANO-AntivirusTrojan.Win64.HackKMS.deintz
SUPERAntiSpywareTrojan.Agent/Gen-HackMS
MicroWorld-eScanTrojan.GenericKD.42202272
TencentMalware.Win32.Gencirc.10b0ce2f
Ad-AwareTrojan.GenericKD.42202272
SophosMal/Generic-R + Mal/SwiftG-X
ComodoMalware@#3kdeq62htxh8y
BitDefenderThetaGen:NN.ZelphiF.34804.pnKfaWb!Vpmj
VIPRETrojan.Win32.Generic!BT
TrendMicroHKTL_AUTOKMS
McAfee-GW-EditionBehavesLike.Win32.DlHelper.tc
FireEyeGeneric.mg.7d7417e8d80536f1
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GenericKD.qb
WebrootW32.Trojan.GenKD
eGambitUnsafe.AI_Score_98%
Antiy-AVLRiskWare[RiskTool]/Win32.ProcPatcher
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftHackTool:Win32/AutoKMS
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Generic.D283F4A0
AegisLabHacktool.Win64.KMSAuto.3!c
ZoneAlarmHackTool.Win64.KMSAuto.b
GDataTrojan.GenericKD.42202272
AhnLab-V3HackTool/Win32.WinActivator.C975148
McAfeeGenericRXAA-AA!7D7417E8D805
MalwarebytesMalware.AI.282495394
PandaTrj/Genetic.gen
TrendMicro-HouseCallHKTL_AUTOKMS
RisingTrojan.Tiggre!8.ED98 (CLOUD)
YandexTrojan.GenAsa!sw8sGmZk7Rg
IkarusPUA.HackKMS
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/HackKMS
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/HackTool.AutoKMS.HwsBmUgA

How to remove Malware.AI.282495394?

Malware.AI.282495394 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment