Malware

Malware.AI.4286517512 removal instruction

Malware Removal

The Malware.AI.4286517512 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4286517512 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4286517512?


File Info:

crc32: BE7C6014
md5: 3b2f77eec6fc06e9575c4747a08be0e8
name: 3B2F77EEC6FC06E9575C4747A08BE0E8.mlw
sha1: db4d7eb48d9729fa8fabcd975a82e8cbd18b1e84
sha256: 5f7e8e33431cb3c61ae8f65b8a2d3396bf14a640a1df814f4810bb974dcf153e
sha512: 7d2bb45bbc0f94ef61b04596f8d5f97eb2c69b3a7f4910eca6356ab27e845f0afea3803b603984e56f4311619b4e6775b5ece77ab76fcfd5249535e0b2dbd188
ssdeep: 24576:28WO84AOs9LJf1Rf+HnHUbN3yJ7waMw/Yek67o:2b4XsFcHnyN6x/Yek67
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2008-2009 Trend Micro Incorporated. All rights reserved.
InternalName: TmProxy
FileVersion: 1.7.1.0
CompanyName: NAVITELxae
1: Trend Micro Network Security Components is a registered trademark of Trend Micro Incorporated.
ProductVersion: 6.1.7.4
Translation: 0x0409 0x04b0

Malware.AI.4286517512 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053cc531 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Agent.DHGI
CylanceUnsafe
ZillyaTrojan.Regsup.Win32.6668
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.15556d0e
K7GWTrojan ( 0053cc531 )
Cybereasonmalicious.ec6fc0
CyrenW32/Nymaim.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GLUI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.DHGI
NANO-AntivirusTrojan.Win32.Regsup.fjnyqr
MicroWorld-eScanTrojan.Agent.DHGI
TencentMalware.Win32.Gencirc.10ba4947
Ad-AwareTrojan.Agent.DHGI
SophosMal/Generic-S
ComodoTrojWare.Win32.Regsup.NR@7wfx07
BitDefenderThetaGen:NN.ZexaF.34294.fz0@aar50Jmc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXGN-NX!3B2F77EEC6FC
FireEyeGeneric.mg.3b2f77eec6fc06e9
EmsisoftTrojan.Agent.DHGI (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Regsup.bbu
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28AED60
MicrosoftTrojan:Win32/Occamy.C5F
GDataTrojan.Agent.DHGI
TACHYONTrojan/W64.Agent.1138176
AhnLab-V3Malware/Win32.Generic.C2778272
Acronissuspicious
McAfeeGenericRXGN-NX!3B2F77EEC6FC
VBA32BScope.Trojan.Regsup
MalwarebytesMalware.AI.4286517512
PandaTrj/GdSda.A
RisingDownloader.Nymaim!1.AA57 (CLASSIC)
YandexTrojan.Regsup!9K6nidfVMc4
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.GMQK!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.4286517512?

Malware.AI.4286517512 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment