Malware

What is “Malware.AI.4090960834”?

Malware Removal

The Malware.AI.4090960834 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4090960834 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4090960834?


File Info:

crc32: C1F7051A
md5: 7aa1a21daab51e5c35f050e55b47e6a8
name: 7AA1A21DAAB51E5C35F050E55B47E6A8.mlw
sha1: a4bf7d7373e884123c75f3bbaebd99ba19d519bc
sha256: 628ea8709b6195e11eb6fa2d138503ba72169322d70593480630046a9bb58dbd
sha512: 79d657da066004630fae0f9e9aa12d90576ab74fdc0b0ad8b281cedf050618ff75bb27631841c1171e75c2d8e1be1c178ee63d505028aacd0cad7ada6f1b63b6
ssdeep: 12288:AkkqlZmutTZV/qb9ylN28aE2GThX8xbVryxuDabE2g7qBqLPDznzfNcNE:71NZEbCfCGTqxUxWabE2uqBqznz1c
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: das
InternalName: as
FileVersion: asd
CompanyName:
PrivateBuild: asd
LegalTrademarks:
Comments:
ProductName: MyPad Application
SpecialBuild: d
ProductVersion: as
FileDescription: MyPad MFC Application
OriginalFilename: d
Translation: 0x0409 0x04b0

Malware.AI.4090960834 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 004b92da1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Mulinex.85FBC5E3
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWRiskware ( 004b92da1 )
Cybereasonmalicious.daab51
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.DYAMAR.B
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Keylogger.Deepscan-9640645-0
BitDefenderDeepScan:Generic.Mulinex.85FBC5E3
MicroWorld-eScanDeepScan:Generic.Mulinex.85FBC5E3
Ad-AwareDeepScan:Generic.Mulinex.85FBC5E3
SophosML/PE-A
BitDefenderThetaAI:Packer.46F3A54620
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.7aa1a21daab51e5c
EmsisoftDeepScan:Generic.Mulinex.85FBC5E3 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.XPACK.Gen2
eGambitUnsafe.AI_Score_76%
MicrosoftBackdoor:Win32/Zegost.KM!MTB
GDataDeepScan:Generic.Mulinex.85FBC5E3
McAfeeArtemis!7AA1A21DAAB5
MAXmalware (ai score=87)
MalwarebytesMalware.AI.4090960834
PandaTrj/CI.A
RisingMalware.Heuristic!ET#81% (RDMK:cmRtazql9tLp5ZUfanelng3/+VZf)
IkarusPUA.RiskWare.DYAMAR
FortinetRiskware/DYAMAR
AVGWin32:Malware-gen

How to remove Malware.AI.4090960834?

Malware.AI.4090960834 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment