Malware

Malware.AI.528497397 removal instruction

Malware Removal

The Malware.AI.528497397 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.528497397 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.528497397?


File Info:

crc32: B4C71315
md5: 24b3764067d6ab5da3cb289e2c3516ea
name: 24B3764067D6AB5DA3CB289E2C3516EA.mlw
sha1: e031503344ecb2ec03dd7f115c1925824f63cf16
sha256: 07828b2c4a994827efacea71c564afaafac508dd29fa4842b67eedbe84b5a528
sha512: cc47ef3aa99c843dbdd2be655bc4f07a0c1f18c3a7da2792cc28620c4a028ddcfd104b2c29ab119c3f8ff32d266e6e1ce9711c53c8910f2d7898b166675b34a8
ssdeep: 12288:7hQOEeg2Cx1dS8mTdbUu/WcDPKJMMLY9qz4i8W7a3EweR:9Qxeg2CfdS8mTNU0WcDPK9LY91h6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.528497397 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Kazy.122445
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.067d6a
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/Trojan.FDS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AH
APEXMalicious
AvastMSIL:Bladabindi-IT [Wrm]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Kazy.122445
NANO-AntivirusTrojan.Win32.Kazy.ezfpch
MicroWorld-eScanGen:Variant.Kazy.122445
TencentWin32.Trojan.Generic.Hrpb
SophosMal/Generic-S
ComodoMalware@#1xwt9enho5gbs
BitDefenderThetaGen:NN.ZemsilF.34690.pmW@aWPqOjb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DEJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.24b3764067d6ab5d
EmsisoftGen:Variant.Kazy.122445 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1118346
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.AA
AegisLabTrojan.Win32.Generic.lUtP
GDataGen:Variant.Kazy.122445
McAfeeArtemis!24B3764067D6
MAXmalware (ai score=99)
MalwarebytesMalware.AI.528497397
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DEJ21
RisingBackdoor.MSIL.Bladabindi!1.9DE6 (CLOUD)
YandexTrojan.Agent!Dr+JErEcolc
IkarusTrojan-Ransom.Blocker
FortinetW32/Zapchast.XSZ!tr
AVGMSIL:Bladabindi-IT [Wrm]
Paloaltogeneric.ml

How to remove Malware.AI.528497397?

Malware.AI.528497397 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment