Malware

Malware.AI.4020796198 (file analysis)

Malware Removal

The Malware.AI.4020796198 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4020796198 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits behavior characteristic of Nymaim malware
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
rwtdmzovy.com
jjoriratj.net
yhasetq.in
zrbzpahlx.in
pgfkhttrjdz.in
axymzl.com
czipqwttvf.in
svetqu.net
xmlzusdft.in
dtksojke.in
kjyxchwpdwwr.com
vpqponvqj.com
rhadlqw.in
essjrftbpmqz.in
viqnm.pw
wvxjzuovz.pw
sxdcimw.net
hnusymjjl.net
clqjv.net
ezmzf.com
kyjwtafyffz.in
anjlxeyvsalv.com
nlyzgr.pw
oxpks.in
swdqkewzoka.in
esryksicsf.net
erskzr.net
pmavxjun.net
nrwbt.com
bzttkgv.com
efmxc.net
omytfneamnd.in
jxrftekp.pw
dhagxhujdnr.net
yaqajl.net
tcsneebherf.net
bqachx.com
heqktfa.in
ncmlyqdso.net
oawnseeyxv.pw

How to determine Malware.AI.4020796198?


File Info:

crc32: E5700E8C
md5: 725d8ef698920c171b07bab2efe4702a
name: 725D8EF698920C171B07BAB2EFE4702A.mlw
sha1: 50f2f506d4348401f2cd260ac4394d3bcbb8a812
sha256: 237587e49a4a630d195f9466581f5d6e0f3898898c7cee6f1e72d91a0cf954bc
sha512: c908fe73d1b3bfd6c365a7a78ec6cf541058ca994f159021d43dde66df2b45401ba52dccb685a803176928df2ba155104a1d0a8cd8b15f3087345da311192e2f
ssdeep: 12288:aPgpCqMWxc289UAfkoKa0HhUHEwjq1HdEjhWEFTKb:aPssj2895Ka0HhUHEwjqV2jn5+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: AVKTray
FileVersion: 7.5.2.3
Translation: 0x0409 0x04b0

Malware.AI.4020796198 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052ef101 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.60394
CynetMalicious (score: 100)
ALYacTrojan.Brsecmon.1
CylanceUnsafe
ZillyaTrojan.Generic.Win32.273797
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Generic.f5d36bf8
K7GWTrojan ( 0052ef101 )
Cybereasonmalicious.698920
CyrenW32/Nymaim.FD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Nymaim.BA
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Nymaim.etbeku
MicroWorld-eScanTrojan.Brsecmon.1
TencentMalware.Win32.Gencirc.10babb5f
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-S
ComodoMalware@#18mmb0ri166kh
BitDefenderThetaGen:NN.ZexaF.34294.Tq0@aWIVBoak
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXCW-KY!725D8EF69892
FireEyeGeneric.mg.725d8ef698920c17
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bnclk
AviraHEUR/AGEN.1106828
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2222176
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/RL.Generic.R242510
Acronissuspicious
McAfeeGenericRXCW-KY!725D8EF69892
MAXmalware (ai score=99)
VBA32Trojan.Regsup
MalwarebytesMalware.AI.4020796198
PandaTrj/GdSda.A
RisingDownloader.Nymaim!1.AA57 (CLASSIC)
YandexTrojan.Regsup!ao8el7PC/Og
IkarusTrojan-Downloader.Win32.Nymaim
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CBRX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4020796198?

Malware.AI.4020796198 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment