Malware

Malware.AI.2684346008 (file analysis)

Malware Removal

The Malware.AI.2684346008 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2684346008 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2684346008?


File Info:

crc32: CBAE6318
md5: 3bbb59afdf9bda4ffdc644d9d51c53e7
name: 3BBB59AFDF9BDA4FFDC644D9D51C53E7.mlw
sha1: 1798985f4cc2398a482f2232e72e5817562530de
sha256: be14d781b85125a6074724964622ab05f89f41e6bacbda398bc7709d1d98a2ef
sha512: 498fda648f4308acc78dd4beff5a4a989aeb91a28d5b4c564d107e2263627e544bdfdc93f52c73d42a0cf0e56deda4fc375b3fb291cda18a14b24a0a6a469896
ssdeep: 12288:yTy4OwZ54eKaLr6lMeD4woR8ss+/183KiIv2U6IrD4+ytdhC:l1aP6lR4H5s1VW8II+k
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved
InternalName: netmgr
FileVersion: 5, 1, 2600, 2180
CompanyName: Microsoft Corporation
ProductName: Network Manager
ProductVersion: 5, 1, 2600, 2180
FileDescription: Network Performance and Security Manager
OriginalFilename: netmgr.exe
Translation: 0x0409 0x04b0

Malware.AI.2684346008 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.AnimalFarm.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject.59384
ALYacTrojan.Generic.KDV.486949
MalwarebytesMalware.AI.2684346008
ZillyaDropper.Injector.Win32.8002
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/AnimalFarm.b678f46e
Cybereasonmalicious.fdf9bd
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.QQB
APEXMalicious
AvastWin32:EvilBunny-A [Trj]
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.AnimalFarm.gen
BitDefenderTrojan.Generic.KDV.486949
NANO-AntivirusTrojan.Win32.Inject.xnffv
MicroWorld-eScanTrojan.Generic.KDV.486949
TencentMalware.Win32.Gencirc.114cb8e5
Ad-AwareTrojan.Generic.KDV.486949
ComodoMalware@#2tt5l7wlioqb8
BitDefenderThetaGen:NN.ZexaE.34266.Wu0@aGzT9!ki
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BUNEVIL.A
McAfee-GW-EditionGeneric BackDoor.dd
FireEyeGeneric.mg.3bbb59afdf9bda4f
EmsisoftTrojan.Generic.KDV.486949 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Injector.kxh
WebrootW32.Trojan.Gen
AviraTR/Malagent.A.193
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.2BDB16
KingsoftWin32.Troj.injector.ak.(kcloud)
MicrosoftTrojan:Win32/Skeeyah
GDataTrojan.Generic.KDV.486949
TACHYONTrojan/W32.Agent.792064.AJ
AhnLab-V3Dropper/Win32.Injector.C1665679
McAfeeGeneric BackDoor.dd
MAXmalware (ai score=100)
VBA32Trojan.AnimalFarm
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BUNEVIL.A
YandexTrojan.DR.Injector!rxArldvamic
IkarusTrojan-Dropper.Win32.Injector
FortinetW32/Injector.AKDD!tr
AVGWin32:EvilBunny-A [Trj]

How to remove Malware.AI.2684346008?

Malware.AI.2684346008 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment