Malware

Malware.AI.4129515495 removal

Malware Removal

The Malware.AI.4129515495 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4129515495 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Creates a copy of itself

Related domains:

api.ip138.com
dwonload.sz-qudou.net

How to determine Malware.AI.4129515495?


File Info:

crc32: 0242EB89
md5: 28102423c1cf62ad48746007cd028101
name: 28102423C1CF62AD48746007CD028101.mlw
sha1: bafa7490314062f378adc4b9a3188a808709fa1c
sha256: 1e087355a72e5c6b85513aaf4e1b1785ca6eb5f484e3a855d01f89e7ac606532
sha512: 0e48d75900d9a0868c86a529f681b10c41ac2ef499743c766824986d1ad8eb686f5dda7ec5e2e234521dbb2e099b3cf7064fa0d472c4b77b079610e3c4183997
ssdeep: 24576:5SlkQiaeR6gCQbc6z7pJVFLm02FLlKXco4XdO0l:IlkT9FC/6bVFLWLlZoidO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4129515495 also known as:

K7AntiVirusAdware ( 0053e9eb1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.6939
CynetMalicious (score: 100)
CAT-QuickHealPUA.Bundler.S3936668
ALYacGen:Variant.Application.Bundler.196
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWAdware ( 0053e9eb1 )
Cybereasonmalicious.3c1cf6
CyrenW32/S-82206cb5!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.AN potentially unwanted
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Malware.Softcnapp-6940714-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.Bundler.196
NANO-AntivirusTrojan.Win32.Softcnapp.fizpma
MicroWorld-eScanGen:Variant.Application.Bundler.196
TencentMalware.Win32.Gencirc.10b0d1f3
Ad-AwareGen:Variant.Application.Bundler.196
SophosMal/Generic-S + Softcnapp (PUA)
ComodoApplication.Win32.AdWare.Softcnapp.C@7wfak4
BitDefenderThetaGen:NN.ZexaF.34266.2yW@aG3smHfj
TrendMicroTrojanSpy.Win32.TRICKBOT.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.28102423c1cf62ad
EmsisoftGen:Variant.Application.Bundler.196 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cqjhm
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.28877B5
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Application.Bundler.196
AhnLab-V3Adware/Win32.AdLoad.R237401
Acronissuspicious
McAfeeGenericRXGO-EO!28102423C1CF
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.4129515495
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMC
RisingTrojan.Generic@ML.99 (RDML:Jpf4e1gFkBdvWMrq4sjVOw)
YandexTrojan.GenAsa!T2hgklBBNow
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Symmi.CD14!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.4129515495?

Malware.AI.4129515495 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment