Malware

How to remove “Malware.AI.4118642956”?

Malware Removal

The Malware.AI.4118642956 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4118642956 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4118642956?


File Info:

crc32: 9D37E7B2
md5: 562579d1054ab6859497269db946d1d5
name: 562579D1054AB6859497269DB946D1D5.mlw
sha1: 378e50e0f20a3450e358b1bc32ee551c106f09ed
sha256: 11be89c8d3a3a8d9391341b7b6ada0224fb493df0f3a1f76eee7bc5172ddf40e
sha512: 92b8f1abf9069cc2c1a51f672bba6d51a4e1e674a056738206b77fc750eb6538e564892570e170cd92dfe4772eb3738344343883a48f18a8546dc5c0c3832968
ssdeep: 12288:KcErBg6EEJwFbSGJ/7HevKZGjYeKQzP+MiOtiufrQqGf43p7uRKrR7nSIec/Qp3:K911mbSE7oWwHPou0jfeR7SnUuy39y
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x5929x5730x7f51x7edcxb7x7248x6743x6240x6709
FileVersion: 2010.4.25.0
CompanyName: /dyx5929x5730x82f1x96c4
Comments: x5c0ax91cdx4ed6x4ebax52b3x52a8x6210x679cxff0cx5c31x662fx5c0ax91cdx4f60x81eax5df1x3002
ProductName: x300ex8700x95e8x300fx767bx9646x5668
ProductVersion: 2010.4.25.0
FileDescription: x5c0ax91cdx4ed6x4ebax52b3x52a8x6210x679cxff0cx5c31x662fx5c0ax91cdx4f60x81eax5df1x3002
Translation: 0x0804 0x04b0

Malware.AI.4118642956 also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Qqpass.8767
CAT-QuickHealRisktool.Flystudio.16880
McAfeeArtemis!562579D1054A
CylanceUnsafe
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.0f20a3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.QQPass.crtmix
TencentWin32.Trojan.Suspicious.Stub
SophosGeneric PUA DH (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.3mKfami06Mib
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.562579d1054ab685
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.QQPass.nwk
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.7FD93
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.PSE.11B5R9D
TACHYONTrojan-PWS/W32.QQPass.2351104
Acronissuspicious
VBA32BScope.Trojan.Valcaryx
MalwarebytesMalware.AI.4118642956
PandaGeneric Malware
IkarusTrojan.Win32.AVKill
FortinetW32/Generic.AC.1B6E27!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.4118642956?

Malware.AI.4118642956 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment