Malware

Malware.AI.779139605 malicious file

Malware Removal

The Malware.AI.779139605 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.779139605 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.779139605?


File Info:

crc32: 4499467F
md5: 41deb852009dee8341b1862142c45e79
name: 41DEB852009DEE8341B1862142C45E79.mlw
sha1: 29d04c1ab468338690fd75e11a595ba3a52a0b11
sha256: bacd5989c0f8aebcceb4f6268ed626d587d324c91ab45799c5c05d03f196e1d6
sha512: d5eb21bca7661ec9d1ae35f804b8c0e5282db2ebab3bfb5f85bee45323a38418021143b71e1b1d6dc66592c81034d6657315923ddb9db678d3956b1ed23e905d
ssdeep: 24576:bNR2zaQBt37/CZ0w1PeWnzqhqCC6+PEj5hX:KUsrC6aEjn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.23.00
ProductName:
ProductVersion: 1.1.23.00
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Malware.AI.779139605 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Miner.12
ClamAVWin.Malware.Autohk-6995517-0
ALYacGen:Variant.Zusy.319023
CylanceUnsafe
BitDefenderGen:Variant.Zusy.319023
K7GWTrojan ( 004f599c1 )
K7AntiVirusTrojan ( 004f599c1 )
CyrenW32/AutoHK.C.gen!Eldorado
ESET-NOD32Win32/TrojanDropper.AHK.AAO
ZonerTrojan.Win32.73221
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Dropper.Win32.AutoHK.h
ViRobotTrojan.Win32.Agent.812032.I
MicroWorld-eScanGen:Variant.Zusy.319023
Ad-AwareGen:Variant.Zusy.319023
SophosML/PE-A
F-SecureHeuristic.HEUR/AGEN.1106163
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.41deb852009dee83
EmsisoftGen:Variant.Zusy.319023 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Deshacop.iv
AviraHEUR/AGEN.1106163
MicrosoftTrojanDropper:Win32/Zampol.A!bit
ArcabitTrojan.Zusy.D4DE2F
ZoneAlarmTrojan-Dropper.Win32.AutoHK.h
GDataGen:Variant.Zusy.319023
AhnLab-V3Malware/Win32.RL_Generic.R274014
McAfeeDropper-AHK.a
MAXmalware (ai score=88)
VBA32Trojan.Hotkeychick
MalwarebytesMalware.AI.779139605
RisingTrojan.Generic@ML.91 (RDMK:BOG/umpHoHMsRnlXKwYhTA)
IkarusTrojan.Cryptic
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AHK.AAO!tr

How to remove Malware.AI.779139605?

Malware.AI.779139605 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment