Malware

Should I remove “Malware.AI.4293049155”?

Malware Removal

The Malware.AI.4293049155 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4293049155 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Malware.AI.4293049155?


File Info:

crc32: 2764BFF3
md5: a7b3720e4ab9306804dec85f41a7d8e5
name: A7B3720E4AB9306804DEC85F41A7D8E5.mlw
sha1: 59f94c9d5cd06ce6cf2defa9054c516b852c70f3
sha256: a19aaa33ca95b6ac7167fe3ab63d7dbb088228b916124bd683ca7deb7fb2717b
sha512: 001616adbc8a0567d98ac1c736216c81729c80427f76099e1abd6a7459d56574a55c3417ebf5cf02ac5601a7cdf8d277c88f6286baa27590cf44f41e2cc61881
ssdeep: 49152:JJZoQrbTFZY1iaeVdWJV2E4YCcjIdIhHuf:JtrbTA1+LYCcfHW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Malware.AI.4293049155 also known as:

K7AntiVirusTrojan ( 700000111 )
LionicTrojan.Win32.Autoit.m8eX
Elasticmalicious (high confidence)
DrWebBackDoor.Comet.152
CynetMalicious (score: 99)
CAT-QuickHealTrojanPWS.AUTOIT.Zbot.A
ALYacTrojan.GenericKD.2122263
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.110150
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanSpy:Script/Rebhip.e9053aa9
K7GWTrojan ( 700000111 )
Cybereasonmalicious.e4ab93
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Injector.Autoit.SQ
APEXMalicious
AvastAutoIt:MalOb-CI [Trj]
KasperskyTrojan.Win32.Agent.abtub
BitDefenderTrojan.GenericKD.2122263
NANO-AntivirusTrojan.Win32.Agent.cpscmv
MicroWorld-eScanTrojan.GenericKD.2122263
TencentWin32.Trojan.Agent.Lohn
Ad-AwareTrojan.GenericKD.2122263
SophosMal/Generic-R
ComodoSuspicious@#39yek7jk8xeiq
BitDefenderThetaAI:Packer.03A5176019
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Yahlover.tc
FireEyeGeneric.mg.a7b3720e4ab93068
EmsisoftTrojan.GenericKD.2122263 (B)
JiangminTrojan.Agent.cznw
WebrootW32.Malware.Heur.Dkvt
AviraHEUR/AGEN.1101408
MicrosoftTrojan:Win32/Dynamer!dtc
GDataTrojan.GenericKD.2122263
McAfeeArtemis!A7B3720E4AB9
VBA32Trojan.Autoit.Wirus
MalwarebytesMalware.AI.4293049155
PandaTrj/OCJ.D
IkarusTrojan.Win32.Obfuscated
MaxSecureTrojan.Autoit.AZA
FortinetW32/Injector_Autoit.GIA!tr
AVGAutoIt:MalOb-CI [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.4293049155?

Malware.AI.4293049155 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment