Malware

How to remove “Malware.AI.747942345”?

Malware Removal

The Malware.AI.747942345 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.747942345 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.747942345?


File Info:

crc32: E08EA666
md5: 7b2c24bc31be3f49785f1e1c06c45482
name: 7B2C24BC31BE3F49785F1E1C06C45482.mlw
sha1: 8469b8271f293cf063be9283a459306000800feb
sha256: 2056ebc760eb94c31e4d55ed828aaf2ba2d40b25e675feacacbc3abd23ea7ddc
sha512: c742e5cd49f6ec30b6eb5d7f238aca493ae4c5168c7bec6ea82e941ecf0c35b69c5190bf30be7976d1e28234a0d05028fb6777a65f7d04efdbf4f64958c2ddc1
ssdeep: 6144:7T+w2vGY4W4RsiGAYTntF8s3AdOs5Q+dcsEAO+G8yrUI84Z1WnRPd2/H/NTfx8:ewNYOyA2zzAdO8dc3T8BMvWl8XNTfC
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

FileVersion: 1.2.3.10
CompanyName: x51e4x51f0x5de5x4f5cx5ba4
Comments: x7070x9e3dx5b50x8fdcx7a0bx7ba1x7406
ProductVersion: 1.2.3.0
FileDescription: x51e4x51f0x5de5x4f5cx5ba4
OriginalFilename: H_Client.exe
Translation: 0x0804 0x03a8

Malware.AI.747942345 also known as:

K7AntiVirusTrojan ( 004bcce41 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed.551
CynetMalicious (score: 100)
ALYacBackdoor.Hupigon.AAAH
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Obfuscator.577c0692
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.c31be3
CyrenW32/SuspPack.AC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Hupigon
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderBackdoor.Hupigon.AAAH
MicroWorld-eScanBackdoor.Hupigon.AAAH
Ad-AwareBackdoor.Hupigon.AAAH
SophosMal/Generic-R
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.FD8E6BC01F
VIPREVirTool.Win32.Obfuscator.nm (v)
TrendMicroTROJ_GEN.R005C0DET21
McAfee-GW-EditionBehavesLike.Win32.Sytro.fc
FireEyeGeneric.mg.7b2c24bc31be3f49
EmsisoftBackdoor.Hupigon.AAAH (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Hupigon.ayjb
AviraBDS/Hupigon.Gen
MicrosoftBackdoor:Win32/Hupigon
GDataBackdoor.Hupigon.AAAH
AhnLab-V3Backdoor/Win32.Hupigon.R839
Acronissuspicious
McAfeeNew Malware.ka
MAXmalware (ai score=83)
VBA32SScope.Backdoor.Win32.Hupigon.cmpw
MalwarebytesMalware.AI.747942345
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R005C0DET21
RisingPacker.Win32.Agent.bd (CLASSIC)
YandexTrojan.Hupigon.Gen!Pac.6
IkarusTrojan-Dropper.Win32.Hupigon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.KYT!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Malware.AI.747942345?

Malware.AI.747942345 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment