Malware

Should I remove “Malware.AI.134495802”?

Malware Removal

The Malware.AI.134495802 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.134495802 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Malware.AI.134495802?


File Info:

crc32: 02119AA3
md5: 3fb694d6b4acf4b3bd5ed564374ab61c
name: 3FB694D6B4ACF4B3BD5ED564374AB61C.mlw
sha1: 04cf417f2e4f45596c106595ac7f03369841b48e
sha256: 37d46a8a086db64aa7e10c39a8c7301725689356cb9042a4d058d51f25cfb298
sha512: 2c8e940aa55f0ced969da7252842e41107dece173f10cd41094d04c18849b7cb91302654eb2a8ef4b57f8f148b0d3815a924895c5d0858c54618256eff70503c
ssdeep: 12288:4cnC9kMoqAhTSo+95mAHlNo+G4Zl39IqCuD38ZGPo6bW8jJCNt:gOqAhSo+RJd9uuD3/rW8VCNt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015
FileVersion: 4.5.6.541
CompanyName: Appnexus
FileDescription: Suspicion All Laden
LegalTrademarks: Copyright 2015
Comments: Suspicion All Laden
ProductName: WrapperMartyn
ProductVersion: 4.5.6.541
PrivateBuild: 4.5.6.541
OriginalFilename: WrapperMartyn
Translation: 0x0409 0x04b0

Malware.AI.134495802 also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.57862
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00532be81 )
K7AntiVirusTrojan ( 00532be81 )
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.FRQZ
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.oabd
NANO-AntivirusTrojan.Win32.Kryptik.fdgbuw
TencentWin32.Trojan.Foreign.Losc
SophosMal/Generic-S
ComodoMalware@#6wz6uoa8zjqk
BitDefenderThetaGen:NN.ZexaF.34058.Zq0@aC3FvPbi
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPURSNIF.SMZD2
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.3fb694d6b4acf4b3
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Foreign.epc
AviraHEUR/AGEN.1109235
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Glupteba!ml
AhnLab-V3Malware/Win32.Generic.C2572575
Acronissuspicious
McAfeeArtemis!3FB694D6B4AC
MAXmalware (ai score=97)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesMalware.AI.134495802
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_HPURSNIF.SMZD2
YandexTrojan.Foreign!TtyROPUo6f0
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.GHCS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Foreign.HgIASQ0A

How to remove Malware.AI.134495802?

Malware.AI.134495802 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment