Malware

Malware.AI.4166057224 malicious file

Malware Removal

The Malware.AI.4166057224 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4166057224 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
cl10847.tmweb.ru
deus.timeweb.ru

How to determine Malware.AI.4166057224?


File Info:

crc32: 5A1C452C
md5: 52dfc9cedcb11603e769165a86a0abf9
name: 52DFC9CEDCB11603E769165A86A0ABF9.mlw
sha1: 0ebf3f4c8a0cb98ca4bb6dc0558a383112a3b6f8
sha256: ff9531dd12c2fe2859e80695a6343dd6333cb0054d0ca38944a7a0741cde0e3c
sha512: 5ec9123cac9adcf09da75ab3a190398f7b0a1eed3f94a9c61c32804c39314456b49a07122c068e64d0f2600a247bcb5c5bb8ebbb8235ffcb2aa503b20472ab50
ssdeep: 49152:IGSq+dH+RTyRfaagP9sWGKwgcbzKkKeSbtSLa+crxfD3DGUTqDJitmg:F+dHATCzk+rgcbOkTGiN6VDuiIg
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.4166057224 also known as:

K7AntiVirusPassword-Stealer ( 0053bc491 )
DrWebTrojan.PWS.Stealer.25081
CynetMalicious (score: 100)
ALYacDeepScan:Generic.DataStealer.1.DE4455E9
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.2302
AlibabaTrojanPSW:Win32/Cloxer.b43ba3be
K7GWPassword-Stealer ( 0053bc491 )
Cybereasonmalicious.edcb11
CyrenW32/Cloxer.G.gen!Eldorado
ESET-NOD32a variant of Win32/PSW.Agent.OFE
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.DataStealer.1.DE4455E9
NANO-AntivirusTrojan.Win32.Stealer.fknnbo
MicroWorld-eScanDeepScan:Generic.DataStealer.1.DE4455E9
TencentWin32.Trojan-spy.Stealer.Swlj
Ad-AwareDeepScan:Generic.DataStealer.1.DE4455E9
ComodoMalware@#oiy2utc18sym
BitDefenderThetaGen:NN.ZexaF.34294.EoHfaW5Incii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXGP-UC!5A4F78312B84
FireEyeGeneric.mg.52dfc9cedcb11603
EmsisoftDeepScan:Generic.DataStealer.1.DE4455E9 (B)
SentinelOneStatic AI – Suspicious PE
JiangminPacked.Multi.gee
AviraHEUR/AGEN.1105102
Antiy-AVLTrojan/Generic.ASMalwS.2991B4E
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDeepScan:Generic.DataStealer.1.DE4455E9
AhnLab-V3Trojan/Win32.Infostealer.C2862341
McAfeeArtemis!52DFC9CEDCB1
MAXmalware (ai score=84)
VBA32Trojan.Btcon
MalwarebytesMalware.AI.4166057224
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!WJx5Ig79dQ4
IkarusTrojan-PSW.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.OFE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4166057224?

Malware.AI.4166057224 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment