Malware

Malware.AI.4124761950 removal tips

Malware Removal

The Malware.AI.4124761950 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4124761950 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4124761950?


File Info:

crc32: 52668CF3
md5: fb2b515719058422f7f713fe6679b060
name: FB2B515719058422F7F713FE6679B060.mlw
sha1: d3b1fbe538a7228de804d6ec6cb7374998056267
sha256: 5742cac3c6b0adfaf3c47fcecb9b130ee0c19006c1380c2dc31ce023862fa7d7
sha512: fc70d99273efb262b425ff571b13a0b74215a84304b8962ed5ab542c8d9d3f03d107b97b7295511610bd554156ad8715424683443158ba15ba009d7a5803ef30
ssdeep: 1536:KCdwnW/FJ/Qdi52dK4vp+XMWpc5IgRNTU+wR08iY0e1J:KCdz/z6iApnCcQ+Y08Jr1J
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: HKDVR ShenZhen P.R.C (C) 2007
InternalName: HKDVR
FileVersion: 2, 0, 0, 53692
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: HKDVR
SpecialBuild:
ProductVersion: 2, 0, 0, 53692
FileDescription: HKDVR System
OriginalFilename: HKDVR.EXE
Translation: 0x0000 0x04b0

Malware.AI.4124761950 also known as:

K7AntiVirusTrojan ( 003866631 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.4592
CynetMalicious (score: 100)
ALYacTrojan.Generic.7578474
CylanceUnsafe
ZillyaTrojan.Generic.Win32.493162
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirTool:Win32/DelfInject.a2c45721
K7GWTrojan ( 003866631 )
Cybereasonmalicious.719058
BaiduWin32.Trojan.Delf.aa
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.QPD
APEXMalicious
AvastWin32:Delf-TSW [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.7578474
NANO-AntivirusTrojan.Win32.SMSSend.fktkiw
MicroWorld-eScanTrojan.Generic.7578474
TencentBackdoor.Win32.Bdx.b
Ad-AwareTrojan.Generic.7578474
SophosMal/Generic-S
ComodoMalware@#123s4zxdeue5o
BitDefenderThetaAI:Packer.3F57F8891F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0CG521
McAfee-GW-EditionBehavesLike.Win32.Generic.kc
FireEyeGeneric.mg.fb2b515719058422
EmsisoftTrojan.Generic.7578474 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Hupigon.cbry
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.HeurC.KVM099.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C57
ArcabitTrojan.Generic.D73A36A
GDataTrojan.Generic.7578474
Acronissuspicious
McAfeeGenericRXAA-AA!FB2B51571905
MAXmalware (ai score=100)
VBA32TrojanDropper.Injector
MalwarebytesMalware.AI.4124761950
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0CG521
RisingTrojan.Delf!1.6515 (CLASSIC)
YandexTrojan.GenAsa!iYKY4N0NP90
IkarusVirus.Win32.DelfInject
MaxSecureTrojan.Malware.4250086.susgen
FortinetW32/Injector.NTS!tr
AVGWin32:Delf-TSW [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.4124761950?

Malware.AI.4124761950 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment