Malware

Malware.AI.4272059094 malicious file

Malware Removal

The Malware.AI.4272059094 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4272059094 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Malware.AI.4272059094?


File Info:

crc32: D550B54E
md5: ed27c089a4107bb2a38de1a6421dad95
name: ED27C089A4107BB2A38DE1A6421DAD95.mlw
sha1: d9caa3bf60c786886c5cfd9af551bc0486438005
sha256: f13f99c81a1276fe2eb0880121045fe818d92e202bba6a4114aa8fd1b30c0a16
sha512: 8e6f93111ff7c04526b84733a8aed4392a45e046a56537943b81e004dd8fe104f48a8ed245cc9cb94c8d42c313fc68b170bb9c6568416ef223d4f064f8f8b276
ssdeep: 12288:XXjP0ZA78Ep7OhC7/xYzzOOfhpDtdt+9xN:XzP027JpiIxWz9hpDt7UxN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: forest Copyright 1995-Present
InternalName: Federation
CompanyName: forest
PrivateBuild: 7.5.7.8
LegalTrademarks: forest Copyright 1995-Present
Comments: Frisbee Pronominal Prevention
ProductName: Federation
ProductVersion: 7.5.7.8
FileDescription: Frisbee Pronominal Prevention
OriginalFilename: Federation
Translation: 0x0409 0x04b0

Malware.AI.4272059094 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055dd191 )
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.9308
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.271406
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.194413
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Banker.6ea0dbd2
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.9a4107
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
AvastWin32:Malware-gen
ClamAVBC.Win.Packer.Troll-14
KasperskyTrojan-Spy.Win32.Zbot.wjrf
BitDefenderGen:Variant.Graftor.271406
NANO-AntivirusTrojan.Win32.Panda.eahssi
ViRobotTrojan.Win32.Z.Zbot.508416.BH
MicroWorld-eScanGen:Variant.Graftor.271406
TencentMalware.Win32.Gencirc.10c23cd7
Ad-AwareGen:Variant.Graftor.271406
SophosMal/Generic-S
ComodoMalware@#280aakk0s4trb
BitDefenderThetaGen:NN.ZexaF.34266.Fu0@aaaFNugi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Cerber-3
McAfee-GW-EditionBehavesLike.Win32.Downloader.gc
FireEyeGeneric.mg.ed27c089a4107bb2
EmsisoftGen:Variant.Graftor.271406 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.ezpn
WebrootW32.Infostealer.Zeus
AviraHEUR/AGEN.1127203
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.171816F
KingsoftWin32.Troj.Zbot.wj.(kcloud)
MicrosoftPWS:Win32/Zbot
GDataGen:Variant.Graftor.271406
TACHYONTrojan-Spy/W32.ZBot.508416.AG
AhnLab-V3Malware/Win32.Generic.C1338676
Acronissuspicious
McAfeeGenericR-FZG!ED27C089A410
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesMalware.AI.4272059094
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Cerber-3
RisingTrojan.Generic@ML.98 (RDML:dMm8D2kemO3vod2gVTQyEQ)
YandexTrojanSpy.Zbot!M5BulRMdJIM
IkarusTrojan-Spy.Banker.Citadel
FortinetW32/GandCrab.D!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4272059094?

Malware.AI.4272059094 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment