Malware

How to remove “Malware.AI.4259518102”?

Malware Removal

The Malware.AI.4259518102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4259518102 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
myexternalip.com
ocsp.pki.goog
camcomcam.com
balancegym.com
digicomfort.com
computercomfort.nlmodules
vuonsinhthaidieplonghong.com.vn
sken.nl
www.sken.nl
crl.pki.goog
crls.pki.goog
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
r3.o.lencr.org
ocsp.digicert.com

How to determine Malware.AI.4259518102?


File Info:

crc32: 720C5C42
md5: 2faf6a94a7defb5ff88189bf3d6c777b
name: 2FAF6A94A7DEFB5FF88189BF3D6C777B.mlw
sha1: 0ebba89cda568f9680cb069b45c8e2a668906333
sha256: 5b3b2d6bb1f28659a54105b98f807f8bd9db738aedb6b7543d63d309c61258c2
sha512: 20e484f7a1b7b3547202d639659d4eff0f8d0d2909bc0056c88630b229cb7156ed262b5abc974243ceacbf26f9f78f3f4e58d6dd4eab6a3a58bfa845206608c6
ssdeep: 12288:cJdfmGnuaMdDzjiD0sl2NrPvEjD7oDsPYNuIiTxwnz15LAJm:cJdgLo7mz15m
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Dramatisations (C) 2015
InternalName: Comics
FileVersion: 100, 214, 239, 30
CompanyName: IE7Pro.com
ProductName: Enlarged Discordance
FileDescription: Eking
OriginalFilename: Complains.exe

Malware.AI.4259518102 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.38060
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Amonetize.Win32.1663
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaVirTool:Win32/CeeInject.55f1877c
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.4a7def
SymantecTrojan.Gen
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastWin32:TeslaCrypt-CR [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.AVKill.dymjrv
ViRobotTrojan.Win32.TeslaCrypt.Gen.B
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.114c6d23
Ad-AwareTrojan.Cripack.Gen.1
SophosML/PE-A + Troj/Ransom-BRV
ComodoMalware@#vlecpvoyppwp
BitDefenderThetaGen:NN.ZexaF.34796.Bq0@aeHDKfpi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_CRYPTESLA.USVN
McAfee-GW-EditionGenericR-EZO!2FAF6A94A7DE
FireEyeGeneric.mg.2faf6a94a7defb5f
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminVariant.Symmi.rh
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1123563
Antiy-AVLTrojan/Generic.ASMalwS.1572851
MicrosoftVirTool:Win32/CeeInject.gen!E
ArcabitTrojan.Cripack.Gen.1
GDataTrojan.Cripack.Gen.1
AhnLab-V3Trojan/Win32.Teslacrypt.R168154
Acronissuspicious
McAfeeGenericR-EZO!2FAF6A94A7DE
MAXmalware (ai score=87)
MalwarebytesMalware.AI.4259518102
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_CRYPTESLA.USVN
RisingTrojan.Generic@ML.100 (RDML:i58eBHj3AexNmWItNbxE3g)
YandexTrojan.Filecoder!2gk1UcsgPWY
IkarusTrojan.Win32.Filecoder
FortinetW32/Kryptik.EEUA!tr
AVGWin32:TeslaCrypt-CR [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.CeeInject.HxQBEpsA

How to remove Malware.AI.4259518102?

Malware.AI.4259518102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment