Malware

About “Malware.AI.4279726844” infection

Malware Removal

The Malware.AI.4279726844 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4279726844 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ugopow.gyhigtotna.com
ipecho.net
ihazi.gyhigtotna.com
upuq.gyhigtotna.com
utixhfybuj.gyhigtotna.com
ixujyni.gyhigtotna.com
ozisufx.gyhigtotna.com
edfz.gyhigtotna.com
ucyd.gyhigtotna.com
ulhjyh.gyhigtotna.com
ibirensdrt.gyhigtotna.com
elityramalu.gyhigtotna.com
oxrly.gyhigtotna.com
uxemuc.gyhigtotna.com
ukymkrcmabe.gyhigtotna.com
ypumyqshfz.gyhigtotna.com
ulohecepu.gyhigtotna.com
anahajl.gyhigtotna.com

How to determine Malware.AI.4279726844?


File Info:

crc32: 6D4B0F62
md5: b588070978c9415080d87f073ac57c3f
name: B588070978C9415080D87F073AC57C3F.mlw
sha1: 615257d704dbdacbf945ca372ac1c15f03ac5809
sha256: 00d8a401c977cc904c7e16186341063b41f121bfb4cff021ca99019579d8e209
sha512: 08ecabf896ab36c148d84e4c941737ea2834cad04bf6830871fbe7bb062afc3b0ae0ce7b1bac376259df82126e3d49c614ce5d03575e514c0950fcff8901a6df
ssdeep: 12288:VgedFrGPuADesLXtpfnLXziwY457aZcXSJ8wUbj+v24TnWaM:VgeCPucD9pPLXPY457aZGZP+v0t
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2008 - 10 Adobe Systems Incorporated. All rights reserved.
InternalName: LogTransport2
FileVersion: 2, 0, 1, 11
CompanyName: Adobe Systems Incorporated
PrivateBuild: 2, 0, 1, 11
ProductName: LogTransport Application
ProductVersion: 2, 0, 1, 11
FileDescription: LogTransport Application
OriginalFilename: LogTransport2.exe
Translation: 0x0409 0x04b0

Malware.AI.4279726844 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A4
ALYacTrojan.Ransom.Crypto.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1305448
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005224381 )
Cybereasonmalicious.978c94
BaiduWin32.Trojan.Kryptik.alb
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/GenKryptik.BHDN
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Crypto.1
NANO-AntivirusTrojan.Win32.Encoder.evpxap
MicroWorld-eScanTrojan.Ransom.Crypto.1
TencentMalware.Win32.Gencirc.11494c2e
Ad-AwareTrojan.Ransom.Crypto.1
SophosML/PE-A + Mal/Cerber-B
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34686.Hq0@aKTqlSji
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM3
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hh
FireEyeGeneric.mg.b588070978c94150
EmsisoftTrojan.Ransom.Crypto.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen2
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Teerac.I
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.Crypto.1
AhnLab-V3Win-Trojan/Lukitus2.Exp
Acronissuspicious
McAfeeGenericRXDH-VR!B588070978C9
MAXmalware (ai score=100)
VBA32Trojan.Menti
MalwarebytesMalware.AI.4279726844
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM3
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqXhTLzC8kqKE/ORO7LGGmK)
IkarusTrojan.Win32.Filecoder
FortinetW32/Injector.EETM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4279726844?

Malware.AI.4279726844 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment