Malware

Malware.AI.4220816561 removal tips

Malware Removal

The Malware.AI.4220816561 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4220816561 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4220816561?


File Info:

crc32: 8812560D
md5: 5fb572091c58721e7c152fa4ca66d215
name: 5FB572091C58721E7C152FA4CA66D215.mlw
sha1: 6ee683890358045636f4b4544847daf090522fad
sha256: 158a6fde1ff14aa2d833445547da59353226732041f129f7f5f6275eb2be22f4
sha512: ae7fb373151350aad0e8819a3de1518e07ca906aad02c57443cb4b908280c42f10bddfc5a096ef4c4b8ccf1cb0b392dfdce98aa921bac50e71c44a5cb5072aac
ssdeep: 3072:QyVuh1XWViVSBxykI0CDbjVpAT+Q562C4c/4cv3B:FuS8MqknIR6h562C3/3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright xa9 2001-2004 Glen Sawyer
InternalName: MP3GainGUI
FileVersion: 1.02.0005
CompanyName: Snelg Enterprises
ProductName: MP3Gain GUI
ProductVersion: 1.02.0005
FileDescription: MP3Gain GUI
OriginalFilename: MP3GainGUI.exe

Malware.AI.4220816561 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0051e00a1 )
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.40548
CynetMalicious (score: 100)
ALYacTrojan.Zbot.Gen
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.198494
SangforTrojan.Win32.Zbot.MTB
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Kryptik.85a4833b
K7GWTrojan ( 0051e00a1 )
Cybereasonmalicious.91c587
CyrenW32/Trojan.NROE-5749
SymantecRansom.Kovter
ESET-NOD32a variant of Win32/Kryptik.FJBP
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-1816980
KasperskyTrojan-Spy.Win32.Zbot.ziua
BitDefenderGen:Variant.Zusy.210678
NANO-AntivirusTrojan.Win32.Kryptik.fghzay
ViRobotTrojan.Win32.S.Zbot.102400
MicroWorld-eScanGen:Variant.Zusy.210678
TencentMalware.Win32.Gencirc.114b1836
Ad-AwareGen:Variant.Zusy.210678
SophosMal/Generic-S
ComodoMalware@#2hus68rfynw31
BitDefenderThetaGen:NN.ZexaF.34266.gy0@aioBPOp
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_KRYPTIK.QGG
McAfee-GW-EditionTrojan-FKDU!5FB572091C58
FireEyeGeneric.mg.5fb572091c58721e
EmsisoftGen:Variant.Zusy.210678 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Zbot.fogr
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1109543
Antiy-AVLTrojan/Generic.ASMalwS.1C2F92F
KingsoftWin32.Troj.Zbot.xj.(kcloud)
MicrosoftPWS:Win32/Zbot!MTB
GDataGen:Variant.Zusy.210678
TACHYONTrojan-Spy/W32.ZBot.102400.BV
AhnLab-V3Dropper/Win32.Necurs.R189821
McAfeeTrojan-FKDU!5FB572091C58
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesMalware.AI.4220816561
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_KRYPTIK.QGG
RisingTrojan.Generic@ML.98 (RDML:oEHFjhyghGN97D0T+3HPEg)
YandexTrojan.GenAsa!bE3TjMpeJ8o
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.FJBP!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.4220816561?

Malware.AI.4220816561 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment