Malware

What is “Malware.AI.4221852145”?

Malware Removal

The Malware.AI.4221852145 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4221852145 virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

api.xp666.com
download.xp666.com

How to determine Malware.AI.4221852145?


File Info:

crc32: 691567D6
md5: a89628ff94f7bffef5b1feb7765eabd5
name: A89628FF94F7BFFEF5B1FEB7765EABD5.mlw
sha1: d8c7fd90db9289abaf9df7eb954933b6a6602ee5
sha256: f7a44767d416afc23f38e3ea2023a3bfb48c051b6f80c2dd4b9b55ca84a1dbb0
sha512: 19274c1299dda3e1fbca01f9cff05d64f01629a3126f8aed327a97e07fd7c2b880b4200a931da0af82bd9883e0c08eff75923936ca6c93a3b422e80458813818
ssdeep: 24576:9b2sNPwyGpsoHMvqqXVEIrNRrgLCE+VZZ1PvL1/AP+5CufXDwk0LMdE:Z2ps9HXNDgL8ZvZYG5Cufz04dE
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyrightxff08@xff092019
FileVersion: 2.3.7.134
ProductName: __
ProductVersion: 2.3
FileDescription: __
OriginalFilename: appsetupdt.exe
Translation: 0x0409 0x04e4

Malware.AI.4221852145 also known as:

K7AntiVirusTrojan ( 005765551 )
LionicAdware.Win32.ExtendSoft.2!c
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Phonzy
ALYacGen:Variant.Graftor.966545
CylanceUnsafe
ZillyaTrojan.Duote.Win32.325
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaAdWare:Win32/Duote.b03e5059
K7GWTrojan ( 005765551 )
CyrenW32/Trojan.VHBX-7425
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Duote.A
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Trojan.Generic-9877372-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.ExtendSoft.gen
BitDefenderGen:Variant.Graftor.966545
MicroWorld-eScanGen:Variant.Graftor.966545
Ad-AwareGen:Variant.Graftor.966545
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.otwqs
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0PG521
McAfee-GW-EditionGenericRXOZ-LG!A89628FF94F7
FireEyeGen:Variant.Graftor.966545
EmsisoftGen:Variant.Graftor.966545 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.ExtendSoft.d
AviraTR/Redcap.otwqs
Antiy-AVLTrojan/Generic.ASMalwS.3399CBB
MicrosoftTrojan:Win32/Vigorf.A
ArcabitTrojan.Graftor.DEBF91
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.ExtendSoft.gen
GDataGen:Variant.Graftor.966545
McAfeeGenericRXOZ-LG!A89628FF94F7
MAXmalware (ai score=85)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.4221852145
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R06CC0PG521
RisingAdware.Downloader!1.D1AB (CLASSIC)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.118830450.susgen
FortinetW32/Duote.A!tr
AVGWin32:Adware-gen [Adw]
Qihoo-360Win32/Adware.Generic.HgIASX0A

How to remove Malware.AI.4221852145?

Malware.AI.4221852145 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment