Worm

Worm:Win32/Aicat.A!ml information

Malware Removal

The Worm:Win32/Aicat.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Aicat.A!ml virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Worm:Win32/Aicat.A!ml?


File Info:

crc32: FAD5E5E8
md5: 7efb5443cc7fbb148a1992b42a1b284c
name: 7EFB5443CC7FBB148A1992B42A1B284C.mlw
sha1: bddac1f2c2315d36f782be1e0680cb20e073dca0
sha256: 493e9bc018c2e6ab46c0bfcf7e68b419eca8fdb0575e279912748b4bb12849fb
sha512: 71a8bb327eed795bbc7a908c0775c110f9803404f7671884b3bc34096e427503848e9f447486c9997abb781b8c90af5b0ec03b8c0111bc7b0357be8939ceaf3d
ssdeep: 3072:JJtAmUj5Angq5Qp+mztez/NoUIB4tYlO2TyQ79u4mXdjrkMVOS6qk3gjLUVgAIc:9leIg8KgzIY2ejBXdjIhXqk3gj4XvDA
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: ClientVP.exe
FileVersion: 2.0.0.1
CompanyName: YouTube Italia
ProductName: Youtube&Samsung
ProductVersion: 1.0.0.1
FileDescription: YouTube Italia
OriginalFilename: Samsung S9.jpg
Translation: 0x0410 0x04b0

Worm:Win32/Aicat.A!ml also known as:

K7AntiVirusTrojan-Downloader ( 0052ebbe1 )
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30557743
CylanceUnsafe
SangforRansom.Win32.Blocker.kyfo
K7GWTrojan-Downloader ( 0052ebbe1 )
Cybereasonmalicious.3cc7fb
SymantecTrojan Horse
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.DXQ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.kyfo
BitDefenderTrojan.GenericKD.30557743
NANO-AntivirusTrojan.Win32.Blocker.fagwzo
MicroWorld-eScanTrojan.GenericKD.30557743
TencentWin32.Trojan.Blocker.Anqh
Ad-AwareTrojan.GenericKD.30557743
SophosMal/Generic-S
ComodoMalware@#2250p291q3kjg
BitDefenderThetaGen:NN.ZexaF.34692.ky0@a4mq0DpO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.7efb5443cc7fbb14
EmsisoftTrojan.GenericKD.30557743 (B)
JiangminTrojanDownloader.Generic.axax
WebrootW32.Trojan.GenKD
AviraTR/Blocker.dbiga
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2545979
MicrosoftWorm:Win32/Aicat.A!ml
AegisLabTrojan.Win32.Blocker.j!c
GDataTrojan.GenericKD.30557743
TACHYONRansom/W32.Blocker.171008.H
McAfeeArtemis!7EFB5443CC7F
MAXmalware (ai score=95)
VBA32BScope.TrojanRansom.Blocker
PandaTrj/GdSda.A
RisingRansom.Blocker!8.12A (CLOUD)
IkarusWin32.SuspectCrc
FortinetW32/Blocker.KYFO!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Worm:Win32/Aicat.A!ml?

Worm:Win32/Aicat.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment