Malware

About “Malware.AI.941044256” infection

Malware Removal

The Malware.AI.941044256 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.941044256 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware

Related domains:

norjuyujsyninmh.pl
sjtxdhp.xyz
kwsphsp.click
pybnwpaikssk.ru
ofcqbpehtsuus.click
fkfuufcbyrsggf.org
dcahcxgjedud.org

How to determine Malware.AI.941044256?


File Info:

crc32: D8AA19EB
md5: b66eb4bcb2860ef48afbc1378e1ae545
name: B66EB4BCB2860EF48AFBC1378E1AE545.mlw
sha1: a2fcbf6e175afcee58344e6ee0f551fc2fff8d27
sha256: 49a48d4ff1b7973e55d5838f20107620ed808851231256bb94c85f6c80b8ebfc
sha512: 49c07ccc11d71c8fcb83cc9462ce1ba961ff0b22906deb558c9cd4628bd9e458f534b252e066e0ac6d0f220908cf5d046c923db33b10bf7027f52eda809c1a4d
ssdeep: 3072:j9UJ3gySjKLkEfwoZaNEP3N2QdW4BVa7NnnFRdqDGowa9:j61NSjVmaN63NiL4Di
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Southsoftware.com, 2002-2015
InternalName: #dvenced Task Scheduler 32-bit Edition
FileVersion: 4.1.0.612
CompanyName: Doubtsoftware.com
ProductName: Advanced Task Scheduler 32-bit Edition
ProductVersion: 4.1.0.612
FileDescription: Advanced Task Scheduler 32-bit Edition
OriginalFilename: Bifscheduler_edmin.exe
Translation: 0x0409 0x04e2

Malware.AI.941044256 also known as:

BkavW32.EdosapiP.Trojan
K7AntiVirusTrojan ( 004e190c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4287
CynetMalicious (score: 100)
CAT-QuickHealRansomware.Locky.MUE.G5
ALYacTrojan.Ransom.LockyCrypt
CylanceUnsafe
ZillyaTrojan.CryptGen.Win32.3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Locky.27c54ec7
K7GWTrojan ( 004e190c1 )
Cybereasonmalicious.cb2860
BaiduWin32.Trojan.Kryptik.xf
CyrenW32/Locky.G.gen!Eldorado
SymantecRansom.TeslaCrypt
ESET-NOD32a variant of Win32/Kryptik.ESSX
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Locky-30744
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.632459
NANO-AntivirusTrojan.Win32.Encoder.ebhdsa
ViRobotTrojan.Win32.Locky.Gen.B
SUPERAntiSpywareRansom.Locky/Variant
MicroWorld-eScanGen:Variant.Razy.632459
TencentWin32.Trojan.Agentb.Pezm
Ad-AwareGen:Variant.Razy.632459
SophosML/PE-A + Troj/Crypt-H
ComodoTrojWare.Win32.Ransom.Locky.DN@6b4fxf
F-SecureHeuristic.HEUR/AGEN.1120426
BitDefenderThetaGen:NN.ZexaF.34690.jy0@aCy5MTki
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_LOCKY.SMA1
McAfee-GW-EditionBehavesLike.Win32.Worm.ch
FireEyeGeneric.mg.b66eb4bcb2860ef4
EmsisoftGen:Variant.Razy.632459 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agentb.ty
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1120426
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Locky.A
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Razy.D9A68B
AegisLabTrojan.Win32.Agentb.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Locky.AL
TACHYONTrojan/W32.Agentb.162816.B
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeRansomware-FET!B66EB4BCB286
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.941044256
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_LOCKY.SMA1
RisingRansom.Locky!8.1CD4 (CLOUD)
YandexTrojan.GenAsa!/UiXqPFU1Nc
IkarusTrojan-Ransom.Locky
FortinetW32/Kryptik.ERJK!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.941044256?

Malware.AI.941044256 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment