Malware

Malware.AI.4220986489 removal tips

Malware Removal

The Malware.AI.4220986489 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4220986489 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4220986489?


File Info:

crc32: 64183392
md5: 921e564487d7ea70a3a498f92d3db144
name: 921E564487D7EA70A3A498F92D3DB144.mlw
sha1: 1249c7dab3bedad62d3eead8d8b43ec376e18e8e
sha256: 21e484ae248df086a7996d7ef03a4318659e0bb92bf501eea9a88eaf8e8e1f15
sha512: fc3068af76193dd3155ebe4b1af20990c7bc75f32ddd505435c8ecbd7ca8e787667f3b14b39f53d8277792bdcc24a6441278a5728080c186ec20673713fe4501
ssdeep: 1536:ASMbv++NBPGIslZGRgR5c2mMH49hZo7WrB7OKUijwHUNgv/RQtGB99999999999:bMbv+gBC2KxEx0ujc2KxExgujS
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2012
Assembly Version: 1.0.4682.24254
InternalName: Convertisseur de fichiers GMA.exe
FileVersion: 1.0.4682.24254
CompanyName:
LegalTrademarks:
Comments:
ProductName: GmadConvGUI
ProductVersion: 1.0.4682.24254
FileDescription: GmadConvGUI
OriginalFilename: Convertisseur de fichiers GMA.exe

Malware.AI.4220986489 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader25.17797
CynetMalicious (score: 99)
ALYacGen:Variant.Johnnie.68686
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.50271
SangforSuspicious.Win32.Save.a
AlibabaRansom:Win32/Blocker.e7026e9c
Cybereasonmalicious.487d7e
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kfeh
BitDefenderGen:Variant.Johnnie.68686
NANO-AntivirusTrojan.Win32.Blocker.erqzoe
MicroWorld-eScanGen:Variant.Johnnie.68686
TencentWin32.Trojan.Blocker.Hprq
Ad-AwareGen:Variant.Johnnie.68686
SophosMal/Generic-S
ComodoMalware@#23qzg7wsmm063
BitDefenderThetaGen:NN.ZemsilF.34170.Jm0@aCtyiIj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXEF-GD!921E564487D7
FireEyeGen:Variant.Johnnie.68686
EmsisoftGen:Variant.Johnnie.68686 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.phs
AviraHEUR/AGEN.1124771
MicrosoftTrojan:Win32/Occamy.C21
ArcabitTrojan.Johnnie.D10C4E
ZoneAlarmTrojan-Ransom.Win32.Blocker.kfeh
GDataGen:Variant.Johnnie.68686
McAfeeGenericRXEF-GD!921E564487D7
MAXmalware (ai score=99)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.4220986489
PandaTrj/GdSda.A
YandexTrojan.Blocker!sscZFWPEJQw
IkarusTrojan.Blocker
FortinetW32/Blocker.KFEH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4220986489?

Malware.AI.4220986489 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment