Malware

Malware.AI.4002106273 malicious file

Malware Removal

The Malware.AI.4002106273 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4002106273 virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4002106273?


File Info:

crc32: 18AE1E84
md5: 5365b69eb25bb0e74b5f7e463c0d9bcb
name: 5365B69EB25BB0E74B5F7E463C0D9BCB.mlw
sha1: 327933620e85f16b849121e4c0056112023b4813
sha256: 24995391d613d3e200f5d44582697e2a2be50d3a9c0866c1d1f4f8d469bba8d1
sha512: a6f998cb2713db7e0d5cf56d13a4313018fa968b16ee28c0f0ea0ee8a65ed126019d9f8c7c6fea12dc9f7f5d913b9b1f7285c036e6ca7d757e637939ad7aedf9
ssdeep: 12288:EZWxJ6w886KagQmwCowzBV35dGt8nlzC7IdyaElqPrJNS:EW0n86KaBm2wzBV35dGt8nlu7IQaG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Texas Instruments Incorporated
InternalName: Enchase
FileVersion: 1.05
CompanyName: FileZilla Project
LegalTrademarks: Norman Safeground AS
Comments: LSOft TEchnologies INc.
ProductName: Connectify
ProductVersion: 1.05
FileDescription: SUPERAntiSpyware
OriginalFilename: Enchase.exe

Malware.AI.4002106273 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053afe31 )
LionicTrojan.Win32.Fareit.4!c
Elasticmalicious (high confidence)
DrWebTrojan.VbCryptENT.1702
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.Fm1@eKfhz!ii
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.171747
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Fareit.2a14ff5f
K7GWTrojan ( 0053afe31 )
Cybereasonmalicious.eb25bb
CyrenW32/VBKrypt.DR.gen!Eldorado
SymantecDownloader.Ponik
ESET-NOD32a variant of Win32/Injector.DZZB
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Generic-9874288-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.PonyStealer.Fm1@eKfhz!ii
NANO-AntivirusTrojan.Win32.Inject.fgxvdm
MicroWorld-eScanGen:Heur.PonyStealer.Fm1@eKfhz!ii
TencentMalware.Win32.Gencirc.10b46dad
Ad-AwareGen:Heur.PonyStealer.Fm1@eKfhz!ii
SophosML/PE-A + Mal/FareitVB-AB
ComodoTrojWare.Win32.Fareit.DZZ@873ilk
BitDefenderThetaGen:NN.ZevbaF.34266.Fm1@aKfhz!ii
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.FAREIT.SMA.hp
McAfee-GW-EditionBehavesLike.Win32.Fareit.gc
FireEyeGeneric.mg.5365b69eb25bb0e7
EmsisoftTrojan.Injector (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan-PSW.Fareit.dl
AviraHEUR/AGEN.1124490
Antiy-AVLTrojan/Generic.ASMalwS.27DC171
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Heur.PonyStealer.Fm1@eKfhz!ii
TACHYONTrojan-PWS/W32.VB-Fareit.507907.B
AhnLab-V3Win-Trojan/VBKrypt.RP03.X1850
Acronissuspicious
McAfeeFareit-FNA!5365B69EB25B
MAXmalware (ai score=94)
VBA32BScope.Trojan.Fuerboos
MalwarebytesMalware.AI.4002106273
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMA.hp
RisingTrojan.Injector!1.B459 (CLASSIC)
YandexTrojan.GenAsa!+J97VuapRpk
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EAGG!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.4002106273?

Malware.AI.4002106273 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment