Malware

Malware.AI.72991773 (file analysis)

Malware Removal

The Malware.AI.72991773 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.72991773 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.72991773?


File Info:

crc32: EE4385F1
md5: 37c8d4b50b8f4cb3eebdc4ccb4bb91ac
name: 37C8D4B50B8F4CB3EEBDC4CCB4BB91AC.mlw
sha1: 4b40c6a64d60c32c050cc4e1bd605b7106a5bac9
sha256: 211c29bd46f9328498074722518211a6c48c6c0e6e422c473fae06ad48a890bd
sha512: d9ac56136a7dbd666cfc7a806b50b3383128b54b01f1aaf81b9c43aeb946a7c66cc4008db75f410257e1cd796df230312e08250b0718cbdedc65aeebb3f25c64
ssdeep: 6144:GUV9M+a+i2a+i2a+i2a+i2a+i2a+i2aiKQqk:t90i
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Qihu 360 Software Co., Ltd. All rights reserved.
InternalName: SystemRegistryClean
FileVersion: 1, 0, 0, 1003
CompanyName: QIHU 360 SOFTWARE CO. LIMITED
ProductName: 360 SystemRegistryClean
ProductVersion: 1, 0, 0, 1003
FileDescription: 360 SystemRegistryClean
OriginalFilename: SystemRegistryClean.exe
Translation: 0x0409 0x04b0

Malware.AI.72991773 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053485e1 )
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.55423
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Mint.Zamg.O
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.68933
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0053485e1 )
Cybereasonmalicious.50b8f4
CyrenW32/Trojan.BUF.gen!Eldorado
SymantecRansom.Hermes
ESET-NOD32a variant of Win32/Kryptik.GHOY
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Dropper.Bunitu-9895212-0
KasperskyHEUR:Trojan.Win32.NetStream.gen
BitDefenderTrojan.Mint.Zamg.O
NANO-AntivirusTrojan.Win32.Yakes.ffaaef
MicroWorld-eScanTrojan.Mint.Zamg.O
TencentMalware.Win32.Gencirc.10ba529d
Ad-AwareTrojan.Mint.Zamg.O
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanProxy.Bunitu.GHF@7otpks
BitDefenderThetaGen:NN.ZexaF.34294.vq1@a0LEguni
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.SHADE.SMB.hp
McAfee-GW-EditionTrickbot-FRDP!37C8D4B50B8F
FireEyeGeneric.mg.37c8d4b50b8f4cb3
EmsisoftTrojan.Mint.Zamg.O (B)
JiangminTrojan.Yakes.aaec
AviraHEUR/AGEN.1127900
Antiy-AVLTrojan/Generic.ASMalwS.26CF0DF
MicrosoftTrojanProxy:Win32/Bunitu.Q!bit
ArcabitTrojan.Mint.Zamg.O
GDataTrojan.Mint.Zamg.O
AhnLab-V3Trojan/Win32.Bunitu.R231197
Acronissuspicious
McAfeeTrickbot-FRDP!37C8D4B50B8F
MAXmalware (ai score=99)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.72991773
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.SHADE.SMB.hp
RisingTrojan.Kryptik!1.B2B8 (CLASSIC)
YandexTrojan.GenAsa!aq6nWA3cxKI
IkarusTrojan-Ransom.Crypted007
FortinetW32/Kryptik.GLWT!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.72991773?

Malware.AI.72991773 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment