Malware

Malware.AI.1849769105 information

Malware Removal

The Malware.AI.1849769105 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1849769105 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Malware.AI.1849769105?


File Info:

crc32: DC4F399E
md5: 8398bcfaa1decfa192d98c9c1c266909
name: 8398BCFAA1DECFA192D98C9C1C266909.mlw
sha1: 4fbf319b8158979cdf598795259b042a45c131b4
sha256: 316c46294994c5b7ba3177816ff8695fc63206693d52dbd02161858d753225a4
sha512: 1d837fde98966452a40f626b567a343fca147860ae63f39e2d73eb07dfd2d2063bbf3053e1ccf863d944413db4278d5fafcd12883d495c63744d5d61f1f103d2
ssdeep: 1536:6GuYP4RQCP0Kg/ZFzY4Bb153EREKnrzajW9nB5Qqfw9/lrSDLb0A:61RQkq/zY4CRRr1lQ39/lQLb0A
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Malware.AI.1849769105 also known as:

K7AntiVirusTrojan ( 0055dd191 )
Elasticmalicious (high confidence)
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Tovicrypt.7b1479a4
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.aa1dec
CyrenW32/S-b5a1ff1e!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HGEN
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Kryptik.fjoqdq
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentWin32.Trojan.Generic.Eadk
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
ComodoMalware@#1rq13sbdcw3nw
BitDefenderThetaGen:NN.ZexaF.34142.fy1@aq8ttHpQ
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-GJA!8398BCFAA1DE
FireEyeGeneric.mg.8398bcfaa1decfa1
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.CryptXXX.xo
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_85%
Antiy-AVLTrojan/Generic.ASMalwS.1BB4A63
ArcabitTrojan.Ransom.CryptXXX.1
SUPERAntiSpywareRansom.Cerber/Variant
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188553
Acronissuspicious
McAfeeRansomware-GJA!8398BCFAA1DE
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.1849769105
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.100 (RDML:t4ZmqPkKg/eKgdkex2B1lQ)
YandexTrojan.GenAsa!9WV5X3YgrFY
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1849769105?

Malware.AI.1849769105 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment