Malware

Malware.AI.795479391 removal instruction

Malware Removal

The Malware.AI.795479391 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.795479391 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Nymaim malware
  • Checks the version of Bios, possibly for anti-virtualization
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
zwlfwts.net
unmqubhaeme.net
kugkd.in
oovqbcjhdqu.pw
lkdgyklovtd.in
ehgcsetbdh.net
ologvgq.com
rpvlxneqow.in
rnwppxe.com
aqaakkjna.net
hxgal.in
tpkqwsgo.com
dkgctxa.pw
huwel.com
lpbbr.net

How to determine Malware.AI.795479391?


File Info:

crc32: DF5561A4
md5: 99ddadab77eb21c56d16e89c7d133456
name: 99DDADAB77EB21C56D16E89C7D133456.mlw
sha1: d2e8b557a39a5cb254914f317d29b763c85463ba
sha256: dd482264f22a978b70725b8d32c0d6fe45ab2f109b3bf27ea111217647b70c22
sha512: 2bed55d15e4eef7f55ae43a7e1975db3bc78f5f3827e46cceb30ca7a3f50018d721bc43e4bd78b9b5998eccb3c9b57cd64a0b668409c477866cff27725eedf5e
ssdeep: 6144:DbO43pVOdXnofdR9zf03uwt8+RJq0LxgI1GXhJb/ST6:v3pV+3ofVz03DtFJtLxgI1GT/Su
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.795479391 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.110963
FireEyeGeneric.mg.99ddadab77eb21c5
ALYacGen:Variant.Razy.110963
CylanceUnsafe
ZillyaDownloader.Nymaim.Win32.932
SangforMalware
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.b77eb2
BitDefenderThetaGen:NN.ZexaF.34804.5qW@aquf2ylc
CyrenW32/S-2e153855!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.110963
NANO-AntivirusTrojan.Win32.Nymaim.elkpsl
Ad-AwareGen:Variant.Razy.110963
EmsisoftGen:Variant.Razy.110963 (B)
F-SecureHeuristic.HEUR/AGEN.1122132
DrWebTrojan.Inject2.38983
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_NYMAIM_GA3105B2.UVPM
McAfee-GW-EditionBehavesLike.Win32.Dropper.dt
SophosML/PE-A
Paloaltogeneric.ml
JiangminTrojan.Regsup.me
AviraHEUR/AGEN.1122132
Antiy-AVLTrojan/Win32.Nymaim
MicrosoftTrojanDownloader:Win32/Silcon!rfn
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.110963
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Nymaim.C1692115
McAfeeTrojan-FKLA!99DDADAB77EB
MAXmalware (ai score=81)
VBA32Trojan.Nymaim
MalwarebytesMalware.AI.795479391
ESET-NOD32Win32/TrojanDownloader.Nymaim.BA
TrendMicro-HouseCallTROJ_NYMAIM_GA3105B2.UVPM
RisingDownloader.Silcon!8.2D0A (TFE:2:YE42ByZ98HJ)
YandexTrojan.Nymaim!Jkl8EuO4dKI
SentinelOneStatic AI – Suspicious PE
FortinetW32/Nymaim.354F!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.d12

How to remove Malware.AI.795479391?

Malware.AI.795479391 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment