Malware

About “Malware.AI.559714563” infection

Malware Removal

The Malware.AI.559714563 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.559714563 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates known XtremeRAT mutexes

Related domains:

z.whorecord.xyz
a.tomx.xyz
tamerlabed.no-ip.org

How to determine Malware.AI.559714563?


File Info:

crc32: 253F6C27
md5: 60f510f9bbe2e9921b135d987e18e637
name: 60F510F9BBE2E9921B135D987E18E637.mlw
sha1: 2af2a9ca32dc4a7f520cf99db42bbd226f6cf7d8
sha256: b91ec1c36942f0e97ae35278d6e33cc326e1de6aad0ebc4b37011f7cc1ae39af
sha512: ed99344992e1b3223439404250ce8ca0467ca1331fbaabed32d2f798a2be97e920d9618e0b86f0f47ace4b4b5c4fbc5822f35d791817b9f6a2179fbfd483f66b
ssdeep: 12288:KFEt2ONd3DAY/ghf7hvQPQ+FTYWB4y+P9doB2NSwyv/lTfjVCt6em9:UEtBNRmhoP7sWm9d0cyHlTrAtw9
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.559714563 also known as:

K7AntiVirusTrojan ( 700000111 )
LionicTrojan.Win32.Foreign.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Virtumod.11842
CylanceUnsafe
K7GWTrojan ( 700000111 )
Cybereasonmalicious.a32dc4
SymantecRansom.Wannacry
ESET-NOD32Win32/Remtasu.Y
APEXMalicious
AvastAutoIt:ShellCode-A [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.nwma
NANO-AntivirusTrojan.Win32.Virtumod.ewoyrx
TencentWin32.Trojan.Foreign.bksr
SophosMal/Generic-S
ComodoMalware@#2voag0zf8hweu
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Injector.hc
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1111274
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Xtrat.A
McAfeeArtemis!60F510F9BBE2
VBA32Hoax.Foreign
MalwarebytesMalware.AI.559714563
PandaGeneric Malware
IkarusBackdoor.Win32.Xtrat
FortinetW32/Foreign.ABSZ!tr
AVGAutoIt:ShellCode-A [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Foreign.HgAASSkA

How to remove Malware.AI.559714563?

Malware.AI.559714563 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment