Malware

About “Malware.AI.296597562” infection

Malware Removal

The Malware.AI.296597562 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.296597562 virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
citrix.vipreclod.com
a.tomx.xyz

How to determine Malware.AI.296597562?


File Info:

crc32: 60DE207E
md5: 32093dcd8d73371848928310bd9d4f62
name: 32093DCD8D73371848928310BD9D4F62.mlw
sha1: d55322f487e4068e2e2f4ce7609498057aaf4c25
sha256: c80f1790b8239aef9751471f82c07a5192e384646040c409a8fbe48b8e57a2df
sha512: a2ad6fd55f27df184ba55f6015b79269a951e91fe0d84eed4da42a6f6c05a0a6af526c96515af61a95f7d24f8cbffe067c8db18af2d8bb2151ff6da54af22540
ssdeep: 24576:0+9mrnE2Zjll/6b8h3UZrgEu8CkBW+M3nXvIMfhlG144EE/f5DBMY1:0Y2ZjlkWEZw8Jk+EXvIMfP4FRaY1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.296597562 also known as:

K7AntiVirusTrojan ( 0043a4491 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.19306
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Doina.1561
CylanceUnsafe
ZillyaTrojan.Scar.Win32.78818
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0043a4491 )
Cybereasonmalicious.d8d733
BaiduWin32.Trojan.Shyape.a
CyrenW32/Shyape.Q.gen!Eldorado
SymantecTrojan.Sakurel
ESET-NOD32a variant of Win32/Shyape.M
ZonerTrojan.Win32.34396
APEXMalicious
AvastWin32:Shyape-F [Trj]
ClamAVWin.Malware.Scar-6745903-0
KasperskyTrojan.Win32.Scar.okdf
BitDefenderGen:Variant.Doina.1561
NANO-AntivirusTrojan.Win32.Scar.hfuutn
ViRobotTrojan.Win32.Sakula.81408
MicroWorld-eScanGen:Variant.Doina.1561
TencentMalware.Win32.Gencirc.10b9cc9a
Ad-AwareGen:Variant.Doina.1561
SophosMal/Generic-S
ComodoTrojWare.Win32.Shyape.GA@590rbc
BitDefenderThetaAI:Packer.5F9CB66E1F
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.32093dcd8d733718
EmsisoftGen:Variant.Doina.1561 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.aregn
eGambitRAT.Sakula
Antiy-AVLTrojan/Generic.ASMalwS.29197C
MicrosoftTrojan:Win32/Sakurel.B!dha
GridinsoftTrojan.Win32.Downloader.oa!s1
GDataWin32.Trojan.Sakurel.B
AhnLab-V3Malware/Win.Generic.R441166
Acronissuspicious
McAfeeGenericRXAA-AA!32093DCD8D73
MAXmalware (ai score=88)
VBA32Trojan.Scar
MalwarebytesMalware.AI.296597562
PandaTrj/Genetic.gen
RisingTrojan.Shyape!1.A74F (CLASSIC)
YandexTrojan.GenAsa!qk1ef4WVH7Q
IkarusTrojan.Win32.Scar
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Shyape.G!tr
AVGWin32:Shyape-F [Trj]

How to remove Malware.AI.296597562?

Malware.AI.296597562 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment