Malware

About “Malware.AI.4075216139” infection

Malware Removal

The Malware.AI.4075216139 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4075216139 virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4075216139?


File Info:

crc32: 9A880EEC
md5: 29564c7dbd4aa0485ed505fc4c2a4073
name: 29564C7DBD4AA0485ED505FC4C2A4073.mlw
sha1: 0f04985fc9ff8f9b4568b78e46c71bf3469432af
sha256: f4efde724529299b3649c6f8bdd537e747dfcc1494480c340635074a3aac0aad
sha512: 4d805f01f27b4fe1ccad0a2f6332d7be67e2e4c7ef61858b7f45c16767e74886f7964ea018a3cb11336ca67112ae27baea4abc54f7943a1fded3c947674be9ea
ssdeep: 24576:E2JyxgHHU5phzGIvN8KFeWROc/P313mD4/wzXyuZoGe:HkyEhzXDeWROc/f13mDzryuW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4075216139 also known as:

K7AntiVirusVirus ( 0008d6ec1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Legmir.210
CynetMalicious (score: 100)
CAT-QuickHealTrojan.LmirIH.S20025459
ALYacDropped:Generic.Delf.Lmir.2EC949F5
CylanceUnsafe
ZillyaVirus.Sypon.Win32.2
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWVirus ( 0008d6ec1 )
Cybereasonmalicious.dbd4aa
BaiduWin32.Trojan.Sypon.b
CyrenW32/Philis.B
SymantecW32.HLLP.Philis
ESET-NOD32Win32/HLLP.Sypon.B
APEXMalicious
AvastWin32:Delf-AFC [Trj]
ClamAVWin.Trojan.Lmir-22
KasperskyTrojan-GameThief.Win32.Lmir.gen
BitDefenderDropped:Generic.Delf.Lmir.2EC949F5
NANO-AntivirusVirus.Win32.HLLP.ghpt
MicroWorld-eScanDropped:Generic.Delf.Lmir.2EC949F5
TencentVirus.Win32.Lamer.gg
Ad-AwareDropped:Generic.Delf.Lmir.2EC949F5
SophosML/PE-A + W32/Sypon-B
ComodoWin32.HLLP.Sypon.B@3s4r
BitDefenderThetaAI:Packer.9D2A07ED1D
VIPREVirus.Win32.HLLP.Sypon.b (v)
TrendMicroPE_SYPON.B
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dh
FireEyeGeneric.mg.29564c7dbd4aa048
EmsisoftDropped:Generic.Delf.Lmir.2EC949F5 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.LMirInfect.13
AviraTR/PWS.Lmir.JT
Antiy-AVLTrojan/Generic.ASBOL.2557
MicrosoftVirus:Win32/Viking.MR
ZoneAlarmTrojan-GameThief.Win32.Lmir.gen
GDataDropped:Generic.Delf.Lmir.2EC949F5
TACHYONVirus/W32.Philis
AhnLab-V3Win32/Lemir.204800.B
McAfeeW32/HLLP.Philis.gen
MAXmalware (ai score=84)
VBA32Virus.Win32.HLLP.Sypon.a
MalwarebytesMalware.AI.4075216139
PandaTrj/Legmir.ED
TrendMicro-HouseCallPE_SYPON.B
RisingVirus.Syphilis!1.9BE9 (CLASSIC)
YandexTrojan.GenAsa!Hw2KEm396Dk
IkarusVirus.Win32.Viking
FortinetW32/Legendmir.NMD!tr
AVGWin32:Delf-AFC [Trj]

How to remove Malware.AI.4075216139?

Malware.AI.4075216139 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment