Malware

Malware.AI.4113696480 malicious file

Malware Removal

The Malware.AI.4113696480 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4113696480 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Creates a copy of itself

Related domains:

zipansion.com
cli.re

How to determine Malware.AI.4113696480?


File Info:

crc32: 596DADB9
md5: 222eebd574c95dd83ad12fe094459870
name: 222EEBD574C95DD83AD12FE094459870.mlw
sha1: fe9e734ba67cd1a154fc549e3765b59ffa332232
sha256: e9f54b4d3e7e845bfa7cf8f816f006b50975eb9cab493ec9ba3976e10770d313
sha512: 4e4cfe112c42f7a55839d4f6b74a6bff8f0c5f48389a3257142b892b42d87480494bd6e4e0390313f6bd967e018044afdf7e02063bbf5503abd0515fe75aaa8c
ssdeep: 24576:ZT2OfjS24Pf8QrVtRF35j5G6gvDRIFUW8IsGXKrnqAtU9/9Us:l2Kjp4PUgP15G6QIKW8GuqA+R9j
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.4113696480 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.360836
FireEyeGeneric.mg.222eebd574c95dd8
McAfeeGenericRXAA-AA!222EEBD574C9
CylanceUnsafe
BitDefenderGen:Variant.Zusy.360836
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
CyrenW32/S-d6a54396!Eldorado
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
RisingTrojan.Kryptik!1.D12D (CLASSIC)
Ad-AwareGen:Variant.Zusy.360836
SophosML/PE-A + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.ULPM.Gen
EmsisoftGen:Variant.Zusy.360836 (B)
IkarusTrojan.Win32.Injector
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Wacatac.DE!ml
ArcabitTrojan.Zusy.D58184
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.360836
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4299418
BitDefenderThetaGen:NN.ZexaF.34804.unW@aOrsNaf
ALYacGen:Variant.Zusy.360836
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4113696480
ESET-NOD32a variant of Win32/Injector.DZQA
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FFP!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Malware.AI.4113696480?

Malware.AI.4113696480 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment