Malware

Malware.AI.990761434 (file analysis)

Malware Removal

The Malware.AI.990761434 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.990761434 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

microsoftlogin.linkpc.net

How to determine Malware.AI.990761434?


File Info:

crc32: EC05AAD3
md5: b353e254c697d31c68622ef02cbd7569
name: B353E254C697D31C68622EF02CBD7569.mlw
sha1: dc48189e0cb95edfe9ce0b80bd4c9f6d890b2e62
sha256: 7861c3f83dc060f911123626fba4241feb8ab0d1d19bd7cfb9ee7f6c6be902a0
sha512: 2fc72228b1bf9f5ad79ae5e2daa6a37c3ee76a3067ec36577c30b525dc046cbb34940d3ce8b286524233f1d23dfd38fbc0ae3f848ab2a967c51fd97e48a20dd3
ssdeep: 3072:Yf8no3ZihADxr9j+D/qdvV1Q8U2F/BdCN1UhG6ku:S8oJuAV9j+7qdvVW1UDk
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: WindowsApplication9.exe
FileVersion: 1.0.0.0
ProductName: WindowsApplication9
ProductVersion: 1.0.0.0
FileDescription: WindowsApplication9
OriginalFilename: WindowsApplication9.exe

Malware.AI.990761434 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.22064762
FireEyeGeneric.mg.b353e254c697d31c
Qihoo-360Win32/Ransom.Blocker.HgIASOUA
ALYacTrojan.Generic.22064762
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050f5561 )
BitDefenderTrojan.Generic.22064762
K7GWTrojan ( 0050f5561 )
CrowdStrikewin/malicious_confidence_80% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.keof
AlibabaRansom:Win32/Blocker.9f382a5d
NANO-AntivirusTrojan.Win32.Bladabindi.ercqel
AegisLabTrojan.Win32.Blocker.j!c
Ad-AwareTrojan.Generic.22064762
EmsisoftTrojan.Generic.22064762 (B)
ComodoMalware@#vl6qvkce4j4u
F-SecureHeuristic.HEUR/AGEN.1121236
DrWebBackDoor.Bladabindi.13678
McAfee-GW-EditionGeneric.cfb
SophosMal/Generic-S
IkarusTrojan.MSIL.Krypt
AviraHEUR/AGEN.1121236
MAXmalware (ai score=80)
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Generic.D150AE7A
ZoneAlarmTrojan-Ransom.Win32.Blocker.keof
GDataTrojan.Generic.22064762
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.RL_Generic.R285412
McAfeeGeneric.cfb
MalwarebytesMalware.AI.990761434
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.KHD
RisingRansom.Blocker!8.12A (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.KLI!tr
BitDefenderThetaGen:NN.ZemsilF.34590.nq0@a8dAasc
AVGWin32:Malware-gen
Cybereasonmalicious.4c697d
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.990761434?

Malware.AI.990761434 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment