Malware

Malware.AI.4291476236 information

Malware Removal

The Malware.AI.4291476236 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4291476236 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.baidu.com
www.htuzi.com
huangtuzi1314.lofter.com

How to determine Malware.AI.4291476236?


File Info:

crc32: 4CB4855B
md5: 5696326a827707c117cbb8187b926044
name: 5696326A827707C117CBB8187B926044.mlw
sha1: e10b41f75065294c82d33ded24b24f295c1432f4
sha256: e8e43e2677e4e1318ac7f79b5815f0ac6daa44cc1292a2b2ef12a931af235d94
sha512: f40eb3737314007f839627c926667fae73324e67f9388b19da82cfb21574acf1f05e9dbab975e543f47cc66ed1e4851a4758c177a60c341ae66339c9599378f0
ssdeep: 49152:hRCHJnWP3V19n901d40SH21xMuJ73nLhbx08/8kTLMcxVNnMf0p7cCrqtkhROVxL:eHRi1Xed4n2jMuR3nLhbx08/8k3hbwca
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x8fdbx7a0bx542fx52a8x5668 x7248x6743x6240x6709
FileVersion: 1.2.7.0
CompanyName: x8fdbx7a0bx542fx52a8x5668
Comments: x8fdbx7a0bx542fx52a8x5668
ProductName: x8fdbx7a0bx542fx52a8x5668
ProductVersion: 1.2.7.0
FileDescription: x8fdbx7a0bx542fx52a8x5668
Translation: 0x0804 0x04b0

Malware.AI.4291476236 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 005848221 )
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47298068
ALYacTrojan.GenericKD.47298068
CylanceUnsafe
ZillyaTrojan.Blamon.Win32.2976
K7GWAdware ( 005848221 )
Cybereasonmalicious.750652
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Blamon.gen
BitDefenderTrojan.GenericKD.47298068
TencentMalware.Win32.Gencirc.10cf8376
Ad-AwareTrojan.GenericKD.47298068
SophosGeneric PUA OB (PUA)
DrWebTool.NSudo.1
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.5696326a827707c1
EmsisoftTrojan.GenericKD.47298068 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blamon.beb
AviraTR/Blamon.arvsj
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Woreflint.A!cl
GDataTrojan.GenericKD.47298068
AhnLab-V3Trojan/Win.Generic.C4731658
Acronissuspicious
McAfeeGenericRXAA-AA!5696326A8277
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4291476236
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R035H0CKH21
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:Malware-gen

How to remove Malware.AI.4291476236?

Malware.AI.4291476236 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment