Malware

Malware.AI.359480103 removal instruction

Malware Removal

The Malware.AI.359480103 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.359480103 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.359480103?


File Info:

crc32: 2C0AF8A7
md5: c367e44cc0ea42d98ffeb3a172d48fbe
name: C367E44CC0EA42D98FFEB3A172D48FBE.mlw
sha1: 0c3d09a3d4996ad79acb38cc7de3d6a2ddcdfdc2
sha256: cd900decff0b3285f935e64af2fef3474f2b56b1a55fd82ab56cc89e3dcd30cc
sha512: 62ff5a318e38bddacdd3dd0156e46c3fb626ca6dc4cb53b9c0c459245a1396d780e03f9564aed7f5b881dbbec259e0325e4fc8613999a98344a21157fba23b4e
ssdeep: 6144:rI92pt8dfNZk85GlSLRDmNDwXsSTzcePRdsxBFQdU0AD:r4my5Nq3EtmNDwcWJOxBWy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2012
InternalName: PmsAgent
FileVersion: 1, 0, 0, 2
ProductName: PmsAgent Application
ProductVersion: 1, 0, 0, 2
FileDescription: PmsAgent Application
OriginalFilename: PmsAgent.exe
Translation: 0x0409 0x04b0

Malware.AI.359480103 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004ea21e1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.23743
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Doina.7154
CylanceUnsafe
ZillyaTrojan.Urelas.Win32.288
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaBackdoor:Win32/Urelas.d2f902df
K7GWTrojan ( 004ea21e1 )
Cybereasonmalicious.cc0ea4
CyrenW32/A-5f1f83ac!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Urelas.E
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Urelas-6804264-0
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Doina.7154
NANO-AntivirusTrojan.Win32.TrjGen.bcvnps
MicroWorld-eScanGen:Variant.Doina.7154
TencentMalware.Win32.Gencirc.10b0d467
Ad-AwareGen:Variant.Doina.7154
SophosMal/Generic-S
ComodoMalware@#95f20tj98m3m
BitDefenderThetaGen:NN.ZexaE.34126.qmMfaq31WPgi
VIPRETrojan.Win32.Urelas.a (v)
TrendMicroTSPY_URELAS_BK08450D.TOMC
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.c367e44cc0ea42d9
EmsisoftGen:Variant.Doina.7154 (B)
JiangminTrojan/Generic.amxgl
AviraBDS/Backdoor.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.9AF951
MicrosoftRansom:Win32/StopCrypt!ml
ArcabitTrojan.Doina.D1BF2
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Variant.Doina.7154
AhnLab-V3Trojan/Win32.PbBot.R38304
Acronissuspicious
McAfeeGenericRXAA-AA!C367E44CC0EA
MAXmalware (ai score=100)
VBA32BScope.Trojan.AVKill
MalwarebytesMalware.AI.359480103
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_URELAS_BK08450D.TOMC
YandexTrojan.Urelas!252MXLlVVeQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.E!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.359480103?

Malware.AI.359480103 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment