Malware

How to remove “Malware.AI.921684878”?

Malware Removal

The Malware.AI.921684878 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.921684878 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.921684878?


File Info:

crc32: C6EE41DD
md5: 0b3262591cf023c82834c2ee4be0af24
name: 0B3262591CF023C82834C2EE4BE0AF24.mlw
sha1: 5f0c0ad1b492cb1a01b384e4b34e5e4c096249ee
sha256: 41d16658dafd9af708473fc84dc69e2af0c83305331b468e77dbbfbfbf52857e
sha512: 175cf57c666e304071440dd9b32276c0d1d0bdbacba338babd474f537cd7e3883b9e7d2fe01c456cd614f5b241efd2f4a2451d6bc5a19937c0dc8aaac89dd653
ssdeep: 1536:K/4SqJUVMvbg67Iy/ntecoqSYn9JeYhl4SqJUVMvbg67I3LZcoqSYn9wyBtV2KF:KJejI9cAYnTeYxejI3LZcAYniyF1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2011
Assembly Version: 1.0.0.0
InternalName: wersvc.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
Comments: wersvc
ProductName: wersvc
ProductVersion: 1.0.0.0
FileDescription: wersvc
OriginalFilename: wersvc.exe

Malware.AI.921684878 also known as:

K7AntiVirusTrojan ( 00530c291 )
DrWebTrojan.MulDrop3.45177
CynetMalicious (score: 99)
ALYacGen:Variant.MSILDrop.6
CylanceUnsafe
ZillyaTrojan.Generic.Win32.57401
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win64/LockScreen.09a1d0dc
K7GWTrojan ( 00530c291 )
Cybereasonmalicious.91cf02
CyrenW32/S-3e5dc3f2!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/LockScreen.O
APEXMalicious
AvastWin64:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.MSILDrop.6
NANO-AntivirusTrojan.Win64.LockScreen.fhurfb
MicroWorld-eScanGen:Variant.MSILDrop.6
TencentWin32.Trojan.Generic.Fhy
Ad-AwareGen:Variant.MSILDrop.6
SophosMal/Generic-R
ComodoMalware@#2mrbd4zss1g6y
BitDefenderThetaGen:NN.ZemsilF.34770.gm3@aquHZgc
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.0b3262591cf023c8
EmsisoftGen:Variant.MSILDrop.6 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.E27F78
MicrosoftBackdoor:Win32/Bladabindi!ml
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.MSILDrop.6
AhnLab-V3Trojan/Win32.LockScreen.C3275701
McAfeeArtemis!0B3262591CF0
MAXmalware (ai score=100)
VBA32Hoax.Fullscreen
MalwarebytesMalware.AI.921684878
PandaTrj/GdSda.A
YandexTrojan.Fullscreen!WUmUut2aRrI
IkarusTrojan-Ransom.Fullscreen
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/LockScreen.O!tr
AVGWin64:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win64/TrojanDropper.Generic.HgAASRMA

How to remove Malware.AI.921684878?

Malware.AI.921684878 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment