Malware

Malware.AI.2944859310 removal

Malware Removal

The Malware.AI.2944859310 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2944859310 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
s1.spbot.cc
s2.spbot.cc
s3.spbot.cc
auth.spbot.cc
os.spbot.cc

How to determine Malware.AI.2944859310?


File Info:

crc32: D63C4AC2
md5: 0163597651fed63665c8183ba9b4c023
name: 0163597651FED63665C8183BA9B4C023.mlw
sha1: b1fba9f147cda6b19df9a1e75df53ebec3f47ef5
sha256: 891dcbacb96d7cd81f3745a5658a2a4250b1d7fa84bcf4b8635c18fa2dd6673c
sha512: e4a4baba29a2fbb2e06e792fcb02bae3a0a2a3a3c496fc5646aa36bf612bfd096354d7bd44daac6518f662a6c60fd09c7300b860facfd0613b1d96d53f1adda4
ssdeep: 24576:DSxF2Dl7nv4RP9+oq8lCYmu839U3/Aw4xetXCyILIbI/UyiOTIhRYjjYEV8Pjou:WxF2lngRP9xV3ue3/Aw4x6SIbhwaijj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x6e05x5e73x8c03x2121x3001x414
FileVersion: 1.3.10.45
CompanyName: x6e05x5e73x8c03x2121x3001x414
Comments: x5c0fx7a0bx5e8fx52a9x624b
ProductName: x5c0fx7a0bx5e8fx52a9x624b
ProductVersion: 1.3.10.45
FileDescription: x5c0fx7a0bx5e8fx52a9x624b
Translation: 0x0804 0x04b0

Malware.AI.2944859310 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.967098
CylanceUnsafe
K7GWAdware ( 0050718d1 )
Cybereasonmalicious.147cda
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Poison.jvcs
BitDefenderGen:Variant.Graftor.967098
MicroWorld-eScanGen:Variant.Graftor.967098
TencentWin32.Backdoor.Poison.Crb
Ad-AwareGen:Variant.Graftor.967098
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34050.Dz0baOquAKkb
TrendMicroTROJ_GEN.R005C0PGU21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.0163597651fed636
EmsisoftGen:Variant.Graftor.967098 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ASPM.Gen
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.Graftor.DEC1BA
GDataGen:Variant.Graftor.967098
AhnLab-V3Trojan/Win.Generic.C4551455
Acronissuspicious
McAfeeGenericRXPJ-GL!0163597651FE
MAXmalware (ai score=83)
VBA32BScope.Trojan.Fuerboos
MalwarebytesMalware.AI.2944859310
TrendMicro-HouseCallTROJ_GEN.R005C0PGU21
YandexBackdoor.Poison!jw/6Ly4a10g
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2944859310?

Malware.AI.2944859310 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment