Malware

Should I remove “Malware.AI.721955038”?

Malware Removal

The Malware.AI.721955038 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.721955038 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.721955038?


File Info:

crc32: 06D03D55
md5: ab3085a0b0965a81285c8e671bbe962f
name: AB3085A0B0965A81285C8E671BBE962F.mlw
sha1: 006b2cade8274f861b5ef4a4ede334541b4c04b0
sha256: 2385e31cb779afd2ea864d0c05d576ef2ffc01b10b942c1a521185de3c309758
sha512: 8bc61d61c7ae8d8d7d691424d02d255f5969124808561e094e4018431d062be53aed2129e8cbac8ec3075f8d585581a76805f6d3ad04b3369b4877311d6cd515
ssdeep: 49152:VH9j4W3Vkceq+HWHw48xJi/T95L31StZivQWE5drWnNF:xF3ychoAwnxJiv1y4vQv5knN
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.721955038 also known as:

K7AntiVirusTrojan ( 004d69801 )
DrWebTrojan.DownLoader23.38387
ALYacGen:Variant.Icirac.7
CylanceUnsafe
SangforTrojan.Win32.BestaFera.abhg
K7GWTrojan ( 004d69801 )
Cybereasonmalicious.0b0965
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.CMBS
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Banker.Win32.BestaFera.abhg
BitDefenderGen:Variant.Icirac.7
NANO-AntivirusTrojan.Win32.BestaFera.engsap
MicroWorld-eScanGen:Variant.Icirac.7
TencentWin32.Trojan-banker.Bestafera.Lmua
Ad-AwareGen:Variant.Icirac.7
ComodoMalware@#3oh1zvmjo6w3b
BitDefenderThetaAI:Packer.2A99FE8218
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.ab3085a0b0965a81
EmsisoftGen:Variant.Icirac.7 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ghwd
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.22DAC85
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Icirac.7
AhnLab-V3Trojan/Win32.RL_BestaFera.R354958
McAfeeArtemis!AB3085A0B096
MAXmalware (ai score=85)
VBA32Trojan-Banker.BestaFera
MalwarebytesMalware.AI.721955038
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazpv1j6vHMDnP1cpnIb7aJmU)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.CMBS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.721955038?

Malware.AI.721955038 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment