Malware

How to remove “Malware.AI.4228111208”?

Malware Removal

The Malware.AI.4228111208 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4228111208 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

z.whorecord.xyz
soft.520zm.com
a.tomx.xyz

How to determine Malware.AI.4228111208?


File Info:

crc32: 3B2BC1F9
md5: 0a9bd655854ca3d98ca124a1dcc78c7c
name: 0A9BD655854CA3D98CA124A1DCC78C7C.mlw
sha1: 9b651b93903266a255c9324853a8ecc4c3067f86
sha256: 642efe73da8cb84c07fbcc7f5c80727ad1f9102c84e350c02d6def757920304f
sha512: 4fd7b907b6200e1f65dc6f530848c4faf9fc16343401430edb63141170d06069e91c3e987db2310d783e2d7b9d8e6550c867bb4ca367e651ff2b40ff4a8adbad
ssdeep: 49152:YEVUceBzhXiIjjECNpM6Hoi+aGPwe/L/hkq3U/:YE3+hlvEKpePweNzU/
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2010-2018 soft.520zm.com All rights reserved.
FileVersion: 2.0.0.0
Comments: x7effx8272x5355x6587x4ef6x5c01x88c5x5de5x5177
Productname: x7effx8272x5355x6587x4ef6x5c01x88c5x5de5x5177
ProductVersion: 2.0
FileDescription: x7effx8272x5355x6587x4ef6x5c01x88c5x5de5x5177
Translation: 0x0804 0x04b0

Malware.AI.4228111208 also known as:

K7AntiVirusTrojan ( 700000111 )
CynetMalicious (score: 100)
CylanceUnsafe
SangforSuspicious.Win32.AGGR.AutoitItV3ModGUIDMark2
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaPacked:Win32/Generic.b70e91c3
K7GWTrojan ( 700000111 )
Cybereasonmalicious.390326
ESET-NOD32a variant of Win32/Packed.AutoIt.PC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Adware.Autoit-7350688-0
TencentWin32.Trojan.Redcap.Hfn
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.0a9bd655854ca3d9
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Occamy.C64
AegisLabTrojan.Win32.Generic.4!c
McAfeeArtemis!0A9BD655854C
MalwarebytesMalware.AI.4228111208
MaxSecureTrojan.Autoit.AZA
FortinetW32/Generic_PUA_JL
AVGWin32:Malware-gen

How to remove Malware.AI.4228111208?

Malware.AI.4228111208 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment