Malware

How to remove “Malware.AI.4268778867”?

Malware Removal

The Malware.AI.4268778867 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4268778867 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Malware.AI.4268778867?


File Info:

crc32: 32D4782A
md5: b9da74815dd1ff3931189ad4b230a9b4
name: B9DA74815DD1FF3931189AD4B230A9B4.mlw
sha1: 4f089ae9d9897570737d7c0e2db11ef9770dfd59
sha256: b8bf3f9f633403ecf432b767388864fc9349664ea491f34f80d1864c38ae7777
sha512: 74fc4b157402102cafaed4a569115da928a2eb4a041de331ed5f0e4cbb81a2fe15dc79980954840e4250dde337606dc27ce27dac0ea6e83918a2e3c31012d331
ssdeep: 12288:uMKAGLc0UNSz8y6BYUEt/o1p5RanVrXipdGe8meIK9HFxhFvSc7+5I3GMfrh0W8S:pKAGg0P8pBYUY+RanFiOIKdzTK+3JheQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709(C) 2015
InternalName: Ex_List
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Ex_List
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: Ex_List
OriginalFilename: Ex_List.exe
Translation: 0x040f 0x04b0

Malware.AI.4268778867 also known as:

K7AntiVirusTrojan ( 004dcbde1 )
LionicTrojan.Win32.Onion.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.16594
CynetMalicious (score: 99)
CAT-QuickHealRansom.Crowti.A6
ALYacTrojan.Injector.BYO
CylanceUnsafe
ZillyaBackdoor.AndromGen.Win32.1
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Onion.225f7739
K7GWTrojan ( 004dcbde1 )
Cybereasonmalicious.15dd1f
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Trojan.OXLJ-5720
SymantecRansom.CTBLocker
ESET-NOD32Win32/Filecoder.CTBLocker.A
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Onion.gj
BitDefenderTrojan.Injector.BYO
NANO-AntivirusTrojan.Win32.Androm.efgtaw
ViRobotTrojan.Win32.S.Agent.804808
MicroWorld-eScanTrojan.Injector.BYO
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.Injector.BYO
SophosMal/Generic-R + Troj/Ransom-CHW
ComodoMalware@#1r2inoqr2z6d9
F-SecureTrojan.TR/AD.CTBLocker.Y.50
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPCTB.VXXR
McAfee-GW-EditionGeneric.yk
FireEyeGeneric.mg.b9da74815dd1ff39
EmsisoftTrojan.Injector.BYO (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.esl
WebrootW32.Cryptodef.Adek
AviraTR/AD.CTBLocker.Y.50
eGambitUnsafe.AI_Score_59%
Antiy-AVLTrojan/Generic.ASMalwS.1958E00
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Critroni.A
ArcabitTrojan.Injector.BYO
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmTrojan-Ransom.Win32.Onion.gj
GDataWin32.Trojan-Ransom.Filecoder.Q
TACHYONBackdoor/W32.Androm.804808
AhnLab-V3Trojan/Win32.CryptoWall.R176780
McAfeeGeneric.yk
MAXmalware (ai score=100)
VBA32Hoax.Cryptodef
MalwarebytesMalware.AI.4268778867
PandaTrj/WLT.B
TrendMicro-HouseCallRansom_CRYPCTB.VXXR
RisingTrojan.LeakedCert!1.A3FA (CLASSIC)
YandexTrojan.Onion!QY/v5wafyRs
IkarusTrojan.Win32.Filecoder
FortinetW32/Carbanak.A!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.CTBLocker.HwcBEpsA

How to remove Malware.AI.4268778867?

Malware.AI.4268778867 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment