Malware

Malware.AI.4256994071 removal

Malware Removal

The Malware.AI.4256994071 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4256994071 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (14 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.youtube.com
www.bing.com
ocsp.pki.goog
crl.pki.goog
crls.pki.goog
i.ytimg.com
fonts.googleapis.com
fonts.gstatic.com
ssl.gstatic.com

How to determine Malware.AI.4256994071?


File Info:

crc32: 34DCFE4D
md5: b67db6381695f3949cf83827119ba295
name: B67DB6381695F3949CF83827119BA295.mlw
sha1: efbeb0abdec746a29535721155ae67b7b8feb42e
sha256: d954452abe5eaac9432ce169890a5fadf2647f30e81f199ad723aa93b553c672
sha512: 119074155556b04166bf3870360c4cf9ce6f34b068e0eaf5447146e84aae720932e7af6816008b4193e675b8e309387e80a65a5e8d157ee0d9380fa34c517f5a
ssdeep: 1536:+W7ftfkS5g9YOms+gZcQipICdXkNDqLLZX9lItVGL++eIOlnToIfFw8ZvStRH+X:+sFfHgTWmCRkGbKGLeNTBfFHvARH+X
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4256994071 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusUnwanted-Program ( 004b976a1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37148259
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWUnwanted-Program ( 004b976a1 )
Cybereasonmalicious.bdec74
CyrenW32/Trojan.AWQG-5790
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/HostsChanger.A potentially unsafe
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.37148259
MicroWorld-eScanTrojan.GenericKD.37148259
Ad-AwareTrojan.GenericKD.37148259
SophosGeneric PUA OP (PUA)
BitDefenderThetaGen:NN.ZexaF.34050.guW@a4KUrkg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransom.ch
FireEyeGeneric.mg.b67db6381695f394
EmsisoftTrojan.GenericKD.37148259 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_97%
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataTrojan.GenericKD.37148259
AhnLab-V3Trojan/Win.Generic.C4557121
Acronissuspicious
McAfeeRDN/Generic.grp
MalwarebytesMalware.AI.4256994071
TrendMicro-HouseCallTROJ_GEN.R049H09FS21
RisingTrojan.Generic@ML.90 (RDML:OjHVisvpVAtY8CTPUJPILg)
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/HostsChanger
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4256994071?

Malware.AI.4256994071 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment