Malware

Malware.AI.557528245 removal tips

Malware Removal

The Malware.AI.557528245 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.557528245 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Honduras)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
forbidding.marrive.ru

How to determine Malware.AI.557528245?


File Info:

crc32: 1B824F2D
md5: 85b2bf42a888f57ac410fefd267ba618
name: 85B2BF42A888F57AC410FEFD267BA618.mlw
sha1: 12c23dab632629b36deaed5fb5af1de3f032528d
sha256: f8e8f0013360a699b79efc5fc763a7ad2d8fc776033cf6d7bc4c26b59c9105e5
sha512: a28c2ce6717223de34334b973b66b01aae5d9bd5f39a66b0cf52eab6b4528e5b870625bd6c61839d3482b5796f0b3ead47db0fee18f54fdfadfc0775919d94bf
ssdeep: 3072:qIgOWWpP73vxZwrH4cGpMbeh6wmr5uTgyFe5C6wTRMZfa4Av8:qIgOWuxZC4t8H5r5+gyFe5hwtMZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Dream Team
InternalName: Dream Team
FileVersion: 762.3.6.2
CompanyName: Dream Team
ProductName: Dream Team
ProductVersion: 126.4.3.8
FileDescription: Dream Team
OriginalFilename: Dream Team
Translation: 0x002c 0x04b0

Malware.AI.557528245 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.411097
FireEyeGeneric.mg.85b2bf42a888f57a
CAT-QuickHealAdware.Dataric.A5
ALYacGen:Variant.Graftor.411097
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 005173bd1 )
BitDefenderGen:Variant.Graftor.411097
K7GWTrojan-Downloader ( 005173bd1 )
Cybereasonmalicious.2a888f
CyrenW32/Tovkater.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Malware.Tovkater-7668230-0
KasperskyHEUR:Trojan-Downloader.Win32.Generic
AlibabaTrojanDownloader:Win32/Tovkater.3047e46d
NANO-AntivirusRiskware.Win32.TOVus.esvggm
AegisLabTrojan.Win32.Generic.a!c
Ad-AwareGen:Variant.Graftor.411097
EmsisoftGen:Variant.Graftor.411097 (B)
ComodoTrojWare.Win32.TrojanDownloader.Tovkater.DE@7e2kbp
F-SecureHeuristic.HEUR/AGEN.1120926
DrWebTrojan.InstallMonster.2432
ZillyaDownloader.Tovkater.Win32.411
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Tovkater
JiangminAdWare.Generic.nhlx
AviraHEUR/AGEN.1120926
MAXmalware (ai score=100)
Antiy-AVLGrayWare[AdWare]/Win32.AGeneric
MicrosoftPUA:Win32/Vigua.A
ArcabitTrojan.Graftor.D645D9
SUPERAntiSpywareTrojan.Agent/Gen-Symmi
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
GDataGen:Variant.Graftor.411097
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.TOVus.R209346
McAfeeArtemis!85B2BF42A888
VBA32AdWare.TOVus
MalwarebytesMalware.AI.557528245
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.DH
TencentMalware.Win32.Gencirc.10b0e7a6
YandexTrojan.DL.Tovkater!OMgQR2i2bWM
SentinelOneStatic AI – Malicious PE – Downloader
FortinetW32/Tovkater.DG!tr
BitDefenderThetaAI:Packer.8CF8974D1F
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM11.1.7AC5.Malware.Gen

How to remove Malware.AI.557528245?

Malware.AI.557528245 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment