Malware

What is “Malware.AI.4034505145”?

Malware Removal

The Malware.AI.4034505145 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4034505145 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of iSpy Keylogger
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Unusual version info supplied for binary

Related domains:

z.whorecord.xyz
freegeoip.net
a.tomx.xyz

How to determine Malware.AI.4034505145?


File Info:

crc32: 5CE96091
md5: 00f39ffaf5fe6641578b23ea00e10aba
name: 00F39FFAF5FE6641578B23EA00E10ABA.mlw
sha1: f5726cea5b7876b129ab68ada89086cb0469da33
sha256: 1c6ee00be156feaafdc380042d26e986e3d6206a7fa42b03e41b4a5a27fae7fc
sha512: 184d4be4773fc0383fc68588048f90bb4a1af1b73969a64573eda41f49119b496aaab311450040829c066b6a76bef39044458de71412620c6682e04f9e432ee0
ssdeep: 12288:+HyLP2jHTdeOp8m/7eLLubfuP1zOgMgu61:+IAPp8mK6uP1zGg3
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft all right reserved
Assembly Version: 3.10.19.120
InternalName: Windows Defender.exe
FileVersion: 3.10.19.120
CompanyName:
LegalTrademarks:
Comments: Windows Host 32 Manager UI
ProductName: Microsoft Windows Defender
ProductVersion: 3.10.19.120
FileDescription: Microsoft Windows Defender
OriginalFilename: Windows Defender.exe

Malware.AI.4034505145 also known as:

K7AntiVirusTrojan ( 00526c301 )
LionicTrojan.Win32.Reconyc.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24601
ALYacTrojan.Ransom.BlackRuby
CylanceUnsafe
ZillyaTrojan.Reconyc.Win32.21430
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 00526c301 )
Cybereasonmalicious.af5fe6
CyrenW32/BlackRuby.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.InfiniteTear.C
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Reconyc.irxr
BitDefenderDeepScan:Generic.Ransom.Hiddentear.A.9D089698
NANO-AntivirusTrojan.Win32.Reconyc.exzpmv
MicroWorld-eScanDeepScan:Generic.Ransom.Hiddentear.A.9D089698
TencentWin32.Trojan.Raas.Auto
Ad-AwareDeepScan:Generic.Ransom.Hiddentear.A.9D089698
SophosMal/Infitear-A
ComodoMalware@#312ze14q1rchk
BitDefenderThetaGen:NN.ZemsilF.34170.Bm0@aqQdcGc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GJQ!00F39FFAF5FE
FireEyeGeneric.mg.00f39ffaf5fe6641
EmsisoftDeepScan:Generic.Ransom.Hiddentear.A.9D089698 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Reconyc.jgs
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.247AC99
MicrosoftRansom:MSIL/Encruby
ArcabitDeepScan:Generic.Ransom.Hiddentear.A.9D089698
ZoneAlarmTrojan.Win32.Reconyc.irxr
GDataDeepScan:Generic.Ransom.Hiddentear.A.9D089698
McAfeeRansomware-GJQ!00F39FFAF5FE
MAXmalware (ai score=96)
MalwarebytesMalware.AI.4034505145
PandaTrj/GdSda.A
FortinetMSIL/InfiniteTear.C!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4034505145?

Malware.AI.4034505145 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment