Malware

Malware.AI.596253126 (file analysis)

Malware Removal

The Malware.AI.596253126 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.596253126 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r3—sn-4g5e6nzz.gvt1.com

How to determine Malware.AI.596253126?


File Info:

crc32: C82CC1E3
md5: 070a97913d0fb007136dd86fc4d68bf9
name: 070A97913D0FB007136DD86FC4D68BF9.mlw
sha1: 5189b4670cd479f76c020c22621909fdf135d2af
sha256: 72330724efaf4b071c29766c19979dde2c72eb4601ccf89f516c74b6bc139a1d
sha512: 2fcdbd8104c35f2c05cc55af790db7dadd5780c489c594a1ef04b8f692e13af0cd264ec36697893b307c823ecb241a99f8a4db5ec431e4a6f35524899a38060f
ssdeep: 3072:d628xY7R/bL1Ha4zIqkBzdqayZSVz/nCWBFH1opbQUrkMKyz8GLHqRF0l:d60LBNIqkJdqaKqCAdi5r3Vjw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) Dneaugxc CrdfKcqvw bwzimsrKy CmfJsu 2004
InternalName: Setup
FileVersion: 4,7,227,158
CompanyName: Duwqf
ProductName: RmzwviTX
ProductVersion: 4,7,227,158
FileDescription: XwxaiBubR zotteu fehtvpqqgzh wmPjjpl nkhpWz ljBrmPjjq XmVjkxUi
OriginalFilename: setup.exe
Translation: 0x0000 0x04b0

Malware.AI.596253126 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Symmi.17910
FireEyeGeneric.mg.070a97913d0fb007
ALYacGen:Variant.Symmi.17910
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
K7AntiVirusTrojan ( 005326cf1 )
BitDefenderGen:Variant.Symmi.17910
K7GWTrojan ( 005326cf1 )
CyrenW32/Risk.FVFI-5545
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/LockScreen.e7e48c2b
NANO-AntivirusTrojan.Win32.PinkBlocker.ipxsn
ViRobotTrojan.Win32.A.PinkBlocker.179200
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.PinkBlocker!8.4C33 (CLOUD)
Ad-AwareGen:Variant.Symmi.17910
TACHYONTrojan/W32.Agent.179200.DA
EmsisoftGen:Variant.Symmi.17910 (B)
ComodoMalware@#1cvbp0bazulm0
F-SecureHeuristic.HEUR/AGEN.1127093
DrWebTrojan.Siggen2.25098
ZillyaTrojan.PinkBlocker.Win32.1458
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
MaxSecureTrojan.Malware.3578624.susgen
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Smser.fr
WebrootTrojan:Win32/Bojotuc.A
AviraHEUR/AGEN.1127093
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/LockScreen.H
ArcabitTrojan.Symmi.D45F6
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.17910
CynetMalicious (score: 100)
McAfeeArtemis!070A97913D0F
MAXmalware (ai score=100)
VBA32TrojanRansom.LockScreen
MalwarebytesMalware.AI.596253126
PandaTrj/StartPage.DAW
ESET-NOD32a variant of Win32/LockScreen.RV
TencentWin32.Trojan.Lockscreen.Cri
YandexTrojan.GenAsa!7AUkr87lNLc
IkarusTrojan-Dropper.Win32.Blocker
eGambitGeneric.Malware
FortinetW32/SMSer.KR!tr
BitDefenderThetaGen:NN.ZexaF.34590.ku0@ae5q9dmk
AVGWin32:Trojan-gen
Cybereasonmalicious.13d0fb
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCersA

How to remove Malware.AI.596253126?

Malware.AI.596253126 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment