Malware

Malware.AI.4131468362 malicious file

Malware Removal

The Malware.AI.4131468362 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4131468362 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4131468362?


File Info:

crc32: AAAA1A15
md5: 51e6b08949c4b3979f66bea2ff7318e0
name: 51E6B08949C4B3979F66BEA2FF7318E0.mlw
sha1: 8c6142602a6b9b070d4532c05e30c0ec4e717133
sha256: 236cd271a18851e12134e1feb7adaad16f2a4b00ff7ab74a7281bb76dba0a1ab
sha512: d6f8abbc2a9d628927d8a9f47d47f975e066065ff891c28914296ce74240e990e9de82f0474205641e4fdf7cc05099839f5086785b200bd75078740ca8cd9b44
ssdeep: 768:53O/mtr9Vvw3nZQoJQjAfFRP/2i0aHmIUmHzAZtLFGnBv:gkoQVgAYBv
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 0.0.0.0
InternalName: COM Surrogate.exe
FileVersion: 0.0.0.0
CompanyName: Microsoft Corporation
Comments: System.dll
ProductName: Microsoftxae .NET Framework
ProductVersion: 2.0.50727.8922
FileDescription: System.dll
OriginalFilename: COM Surrogate.exe

Malware.AI.4131468362 also known as:

K7AntiVirusTrojan ( 005370091 )
LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.RevetRat.2
ALYacGen:Variant.Razy.356513
CylanceUnsafe
ZillyaTrojan.Agent.Win32.994115
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Injector.fbc04e3f
K7GWTrojan ( 005370091 )
Cybereasonmalicious.949c4b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.TTD
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Variant.Razy.356513
NANO-AntivirusTrojan.Win32.Razy.fiyaum
MicroWorld-eScanGen:Variant.Razy.356513
TencentMsil.Trojan.Agent.Swla
Ad-AwareGen:Variant.Razy.356513
SophosMal/Generic-S
ComodoMalware@#2spphcd89uhj
BitDefenderThetaGen:NN.ZemsilF.34294.fm0@aeCQSAe
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.51e6b08949c4b397
EmsisoftGen:Variant.Razy.356513 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_87%
Antiy-AVLTrojan/Generic.ASMalwS.287CB20
MicrosoftBackdoor:MSIL/Bladabindi!rfn
GDataGen:Variant.Razy.356513
McAfeeArtemis!51E6B08949C4
MAXmalware (ai score=100)
VBA32Trojan.MSIL.Agent
MalwarebytesMalware.AI.4131468362
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Injector
FortinetMSIL/GenKryptik.CDMT!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.4131468362?

Malware.AI.4131468362 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment