Malware

Malware.AI.4263237596 (file analysis)

Malware Removal

The Malware.AI.4263237596 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4263237596 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4263237596?


File Info:

crc32: F6427F07
md5: 926472ab2d8b1714c010ae417a88ac7f
name: 926472AB2D8B1714C010AE417A88AC7F.mlw
sha1: 05400d1e0d78feef17573dbf441845d5b7fded37
sha256: b199885a89253de10f0ca59cf37ac0d0eb5c7d4c0361aa35618a7b2dd9c40b19
sha512: 64cd1c8b2677e309e58188cf7e408ec0649b5d7d2356204a346d7635e68e56dddcc5225cf558b06d6fdc2aee915460f53a08b5e9d3b730482fb8be9e4189ab01
ssdeep: 12288:Vc2rGBMkcDR0N7ALigTQE7HXOY4N5NapUAUY/9vU6:m2a5NcLiKZHXOYm5MpVlvU6
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Malware.AI.4263237596 also known as:

K7AntiVirusTrojan ( 0053a79b1 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Nemesis.1552
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Nisloder.162d0678
K7GWTrojan ( 0053a79b1 )
Cybereasonmalicious.e0d78f
SymantecInfostealer.Rultazo
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Nisloder.gpk
BitDefenderGen:Variant.Nemesis.1552
MicroWorld-eScanGen:Variant.Nemesis.1552
TencentWin32.Trojan.Falsesign.Hrom
SophosMal/Generic-S
ComodoMalware@#2tity32gyz5p0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Nemesis.1552
EmsisoftGen:Variant.Nemesis.1552 (B)
JiangminTrojan.Agent.bzgs
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Occamy.C
AegisLabTrojan.Win32.Agentb.tpDn
GDataNSIS.Trojan-Ransom.GandCrab.L
McAfeeArtemis!926472AB2D8B
MAXmalware (ai score=81)
VBA32Trojan.Nisloder
MalwarebytesMalware.AI.4263237596
PandaTrj/CI.A
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HoMASOUA

How to remove Malware.AI.4263237596?

Malware.AI.4263237596 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment