Malware

Malware.AI.4255919645 removal guide

Malware Removal

The Malware.AI.4255919645 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4255919645 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

one.apitoo.com

How to determine Malware.AI.4255919645?


File Info:

crc32: B3FA59C6
md5: 6946fda9a2bf0eb8eddbf251baec925b
name: 6946FDA9A2BF0EB8EDDBF251BAEC925B.mlw
sha1: 51e3e27a1a51aab4bd8f1ca6dc4769361e6c7e54
sha256: 70cefb3f0ea31c8e1e6ee99d71a27c30a602035a4dfe72e51e00df5a3bd4bc90
sha512: 1ab933acec82a24f14f938906dbdaef814e451653d5efe54339d29f4b23b93a10cfed3aef34a7929bea1b438d84e68fd7912503869b613ff9f9e80eae6dd7e06
ssdeep: 49152:mvqXNK4ACXEaNIxsMDIAxqi9A056/sx0Qrm:mvqXRDEaNIxsUIAAi9A056vQS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2010 Oleg N. Scherbakov
InternalName: 7ZSfxMod
FileVersion: 1.4.1.2100
CompanyName: Oleg N. Scherbakov
PrivateBuild: 2011-04-28
ProductName: 7-Zip SFX
ProductVersion: 1.4.1.2100
FileDescription: 7z Setup SFX (x86)
OriginalFilename: 7ZSfxMod_x86.exe
Translation: 0x0000 0x04b0

Malware.AI.4255919645 also known as:

BkavW32.FamVT.7zipNHc.Trojan
K7AntiVirusAdware ( 004ee86b1 )
Elasticmalicious (high confidence)
DrWebAdware.TopTools.30
CynetMalicious (score: 99)
CAT-QuickHealAdWare.Sogou.N7
ALYacGen:Variant.Doina.12296
CylanceUnsafe
SangforTrojan.Win32.SMG.Heur
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaAdWare:Win32/ArwenApp.331e2e0d
K7GWAdware ( 004ee86b1 )
Cybereasonmalicious.9a2bf0
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Adware.ArwenApp.A
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Doina.12296
NANO-AntivirusRiskware.Win32.TopTools.ecwxjp
MicroWorld-eScanGen:Variant.Doina.12296
TencentMalware.Win32.Gencirc.10b0d238
ComodoApplicUnwnt@#11raw2pxd550y
F-SecureHeuristic.HEUR/AGEN.1123652
BitDefenderThetaGen:NN.ZexaCO.34686.@F0@aOkgt1mP
VIPRETrojan.Win32.Generic!BT
FireEyeGen:Variant.Doina.12296
EmsisoftGen:Variant.Doina.12296 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.Sogou.c
AviraHEUR/AGEN.1123652
eGambitUnsafe.AI_Score_94%
MicrosoftProgram:Win32/Occamy.AA
ArcabitTrojan.Doina.D3008
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Doina.12296
TACHYONTrojan/W32.Agent.1667617
AhnLab-V3PUP/Win32.DownloadAssistant.R181905
McAfeeArtemis!6946FDA9A2BF
MAXmalware (ai score=100)
VBA32Hoax.Blocker
MalwarebytesMalware.AI.4255919645
PandaTrj/CI.A
RisingMalware.Undefined!8.C (CLOUD)
YandexTrojan.Blocker!tdjJ6Vg+oUE
FortinetW32/Blocker.IIXD!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.4255919645?

Malware.AI.4255919645 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment