Malware

What is “Malware.AI.2959105942”?

Malware Removal

The Malware.AI.2959105942 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2959105942 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2959105942?


File Info:

crc32: A0557776
md5: 988a0c01a18e92a42a48b33614f0a446
name: 988A0C01A18E92A42A48B33614F0A446.mlw
sha1: e3935b041c9ff7a12d6c6622d16aad30f6a21bf3
sha256: 54f76bffd468bfb38aaf0adb0fadbfc9fa3a947b420d002c2206e57c805e6000
sha512: 69ff1917e9645bc8bc756f4cfa800b50f3df7594c521f3a059e788cce579aab5eee84b37d02c1f7354ecc5bcd363383f8251ac5d71dd47dd0dcc1791f37db1ba
ssdeep: 12288:uJZJpZFS02i46A9jmP/uhu/yMS08CkntxYRJ:uJZ7ZFiNfmP/UDMS08Ckn3E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: 2010
InternalName: 6
FileVersion: 1.00
CompanyName: rajesh
LegalTrademarks: NEPAL ....RAJESH SHRESTHA
Comments: THIS SOFTWARE IS MADE FOR KIDS
ProductName: CARD PUZZLE BY RAJESH SHRESTHA
ProductVersion: 1.00
FileDescription: CARD PUZZLE
OriginalFilename: 6.exe

Malware.AI.2959105942 also known as:

BkavW32.AIDetectGBM.malware.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.597203
Qihoo-360HEUR/QVM03.0.74F3.Malware.Gen
ALYacGen:Variant.Graftor.597203
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Graftor.597203
Cybereasonmalicious.1a18e9
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan-Spy.Win32.KeyLogger.gen
Ad-AwareGen:Variant.Graftor.597203
EmsisoftGen:Variant.Graftor.597203 (B)
F-SecureTrojan.TR/AD.KutakiStealer.cxjcx
TrendMicroTSPY_VBKEYLOG.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.988a0c01a18e92a4
SophosML/PE-A
IkarusTrojan-Spy.Agent
AviraTR/AD.KutakiStealer.cxjcx
MAXmalware (ai score=82)
ArcabitTrojan.Graftor.D91CD3
ZoneAlarmHEUR:Trojan-Spy.Win32.KeyLogger.gen
GDataGen:Variant.Graftor.597203
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!988A0C01A18E
MalwarebytesMalware.AI.2959105942
ESET-NOD32a variant of Win32/Spy.KeyLogger.NJK
TrendMicro-HouseCallTSPY_VBKEYLOG.SM
RisingSpyware.KeyLogger!1.D278 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_70%
FortinetW32/KeyLogger.NJK!tr
BitDefenderThetaGen:NN.ZevbaF.34574.Hm0@aC!f@sei
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2959105942?

Malware.AI.2959105942 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment