Malware

Malware.AI.526730365 (file analysis)

Malware Removal

The Malware.AI.526730365 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.526730365 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
info.siteken.com

How to determine Malware.AI.526730365?


File Info:

crc32: DBF3C611
md5: 9b495d507e4803a22b740757977846f0
name: 9B495D507E4803A22B740757977846F0.mlw
sha1: 9cc24750cc43917ce947e89ceb3e348f0924161b
sha256: a6ff7e608e4f5a3f6c4c38a52b59835b99567a8fb03ec121dc266d27c915f031
sha512: af16504effc32c52b606988e7a24c933d0505fa4002fe07545d875b349106a59724495bfdbe6506980f042325f94cbf976706e57dcc3db10c77b2d151245c1d8
ssdeep: 49152:OUJKnVa5UOfzzms5/X7o3zXymjTeHr5w2YaOq85J/kzcwgmhR+:vwnVa5NbvpLuXjjTLaO7Wcwgm3+
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Copyright (C) 2014 Shmehao.com. All Rights Reserved.
FileVersion: 1.0.0.1
CompanyName: Shmehao Network Co., Ltd.
LegalTrademarks: Hambo 2
Comments: Hambo 2
ProductName: Hambo 2
Contact: Shmehao Network Co., Ltd.
ProductVersion: 1.0.0.1
FileDescription: Hambo 2 Setup
OriginalFilename: Hambo 2.exe
Translation: 0x0804 0x04e4

Malware.AI.526730365 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0056ba7b1 )
CylanceUnsafe
SangforTrojan.Win32.Zpevdo.A
K7GWRiskware ( 0056ba7b1 )
CyrenW32/PrefChanger.B.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/RiskWare.PrefChanger.B
APEXMalicious
KasperskyTrojan.Win32.StartPage.ufmn
AlibabaTrojan:Win32/StartPage.f3b37868
TencentWin32.Trojan.Startpage.Hufp
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SentinelOneStatic AI – Suspicious PE
Antiy-AVLTrojan/Generic.ASMalwNS.6
KingsoftWin32.Troj.StartPage.uf.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!9B495D507E48
VBA32suspected of Trojan.Downloader.gen
MalwarebytesMalware.AI.526730365
TrendMicro-HouseCallTROJ_GEN.R002H07HK21
FortinetNSIS/StartPage.FICK!tr

How to remove Malware.AI.526730365?

Malware.AI.526730365 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment