Malware

About “Malware.AI.4223399892” infection

Malware Removal

The Malware.AI.4223399892 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4223399892 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • The executable used a known stolen/malicious Authenticode signature

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4223399892?


File Info:

crc32: A391D572
md5: 73c028d199a89c2f04806e43a98a3456
name: 73C028D199A89C2F04806E43A98A3456.mlw
sha1: a23c11b8c812766c2377db15f08c1e422786e7fc
sha256: ee90875b8ff9a45e97c2360ea971d0dac056156a492e1719e21210aaa034abb0
sha512: 8201e40394df3daf0146d24a3b1e606d060b983c1d55dbf4477e511622574eb99444b78de9ffe6529502393d289e57408c89d3ac86f2f849cce050b4637ed14b
ssdeep: 6144:GH50Jf7r1BQAHTWwC3LfXH5fTGxf8K/45X9I4sBODK99VJTu2aL:G5UQAHTBC3LPpY8KetIfOAjRS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4223399892 also known as:

K7AntiVirusTrojan ( 004f3b101 )
Elasticmalicious (high confidence)
DrWebTrojan.Kovter.297
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic.SK1
ALYacGen:Variant.Zusy.377627
ZillyaTrojan.KovterCRTD.Win32.2048
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f3b101 )
Cybereasonmalicious.199a89
BaiduWin32.Trojan.Cerber.b
SymantecRansom.Cerber
ESET-NOD32a variant of Win32/Injector.DBPG
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.377627
NANO-AntivirusTrojan.Win32.MlwGen.eefooh
MicroWorld-eScanGen:Variant.Zusy.377627
TencentMalware.Win32.Gencirc.10bd4c36
Ad-AwareGen:Variant.Zusy.377627
SophosMal/Generic-S
ComodoTrojWare.Win32.Cerber.BAA@6hzktm
BitDefenderThetaGen:NN.ZexaF.34142.BqX@ayTEZiac
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-FNL!73C028D199A8
FireEyeGeneric.mg.73c028d199a89c2f
EmsisoftGen:Variant.Zusy.377627 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Kovter.arz
WebrootW32.Trojan.Kovter
AviraHEUR/AGEN.1128763
eGambitUnsafe.AI_Score_89%
Antiy-AVLTrojan/Generic.ASMalwS.199F7FD
MicrosoftTrojan:Win32/Kovter
GDataGen:Variant.Zusy.377627
AhnLab-V3Trojan/Win32.Cerber.R184342
Acronissuspicious
McAfeeRansomware-FNL!73C028D199A8
MAXmalware (ai score=84)
VBA32BScope.TrojanRansom.Cerber
MalwarebytesMalware.AI.4223399892
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.90 (RDML:Mf/TPz2xEhQp7Qo0+Y9EBQ)
YandexTrojan.Kovter!BAhHc9vRh4g
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.51711
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.4223399892?

Malware.AI.4223399892 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment