Malware

What is “Malware.AI.2916196779”?

Malware Removal

The Malware.AI.2916196779 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2916196779 virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Malware.AI.2916196779?


File Info:

crc32: 6DC2C836
md5: be276baa805460d92775af8b655c17dc
name: BE276BAA805460D92775AF8B655C17DC.mlw
sha1: 92c0eaeef45f85c9ae7d8d2e4300980fdb6600c3
sha256: d400a5d6dffcf73a869ffacdef17e446dc3548111ee848ce3c120063c7ebf185
sha512: 6d5997eb96242e55d27643f2a3c342bd654645d7ba6e168c3e1f7aa1a642290d66c73e82c9e473d28acbb913aa78cc50d32b87c84cde8b9c4706fd3d54a0705a
ssdeep: 1536:wps9jAK1bmzatysDToJGOdk/37eyvfkccyJxkQ08pSEVCnpXv:wps31bmcdToe/iAKyJxkQFphc
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.2916196779 also known as:

K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.HmBlocker.lkxD
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.2723
ClamAVWin.Trojan.Hmblocker-1033
ALYacGen:Variant.Doina.13271
CylanceUnsafe
ZillyaTrojan.HmBlocker.Win32.2732
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/HmBlocker.6d95fa08
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.a80546
CyrenW32/Ransom.E.gen!Eldorado
SymantecTrojan.Ransomlock
ESET-NOD32a variant of Win32/LockScreen.ZD
APEXMalicious
AvastWin32:LockScreen-DE [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.HmBlocker.qr
BitDefenderGen:Variant.Doina.13271
NANO-AntivirusTrojan.Win32.Winlock.bsinq
ViRobotTrojan.Win32.A.HmBlocker.131072.C
MicroWorld-eScanGen:Variant.Doina.13271
TencentWin32.Trojan.Hmblocker.Pgmp
Ad-AwareGen:Variant.Doina.13271
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.E7B40DB11F
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionRansom-FTY!0AA8854AFDCA
FireEyeGeneric.mg.be276baa805460d9
EmsisoftGen:Variant.Doina.13271 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/HmBlocker.bp
WebrootW32.Malware.Gen
AviraTR/Fraud.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.C56367
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDropper:Win32/Wlock.A
GDataGen:Variant.Doina.13271
AhnLab-V3Trojan/Win32.HmBlocker.R2314
Acronissuspicious
McAfeeArtemis!BE276BAA8054
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Papras
MalwarebytesMalware.AI.2916196779
PandaGeneric Malware
RisingTrojan.Win32.Winlock.a (CLASSIC)
YandexTrojan.HmBlocker!U9TTVpz2PGc
IkarusTrojan-Ransom.HmBlocker
MaxSecureTrojan.Malware.2209800.susgen
FortinetW32/Kryptik.19500!tr
AVGWin32:LockScreen-DE [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.2916196779?

Malware.AI.2916196779 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment