Malware

Malware.AI.2798988712 removal instruction

Malware Removal

The Malware.AI.2798988712 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2798988712 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.

Related domains:

delikral.mywire.org
kingspy.mywire.org

How to determine Malware.AI.2798988712?


File Info:

crc32: E05ECF8C
md5: 38b802d5eb05d10c979f12f5049d2ce8
name: 38B802D5EB05D10C979F12F5049D2CE8.mlw
sha1: 9e37763eaf8aa440a0b0b7dbd4c93c42f5ab9d3d
sha256: 6bed821958edf6eec984ab5358507b3188867e22cd2b180401c8b671f6496e4d
sha512: fc8b58212eb7e7447fa4a747ee922fa85d01d61cdb1d42eae2d89b63779e166bf8e1ebdb5d298deb7a3dc4ea8f8e7159dc98f71896abc4a0f25f17a9b0ee1978
ssdeep: 12288:IAAOFnmfkMJrC/drYrhHpB8PGVQ1Oer7VgWqEZE0/iuXAtVj6AURjQ:MOFmfkMJrCVMrppSOVKr7Vg2E0/iuQt
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.23.00
ProductName:
ProductVersion: 1.1.23.00
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Malware.AI.2798988712 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 004f48081 )
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.13678
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.858814
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan-Downloader ( 004f48081 )
Cybereasonmalicious.5eb05d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AutoHK.F
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Dropper.Autohk-7358765-0
KasperskyTrojan-Dropper.Win32.AutoHK.h
BitDefenderGen:Variant.Graftor.858814
MicroWorld-eScanGen:Variant.Graftor.858814
Ad-AwareGen:Variant.Graftor.858814
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.bc
FireEyeGeneric.mg.38b802d5eb05d10c
EmsisoftGen:Variant.Graftor.858814 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.AutoHK.o
MicrosoftTrojan:Script/Phonzy.A!ml
ArcabitTrojan.Graftor.DD1ABE
GDataGen:Variant.Graftor.858814
AhnLab-V3Malware/Win32.RL_Generic.R292180
McAfeeGenericRXKY-BO!38B802D5EB05
MAXmalware (ai score=85)
VBA32Trojan.Hotkeychick
MalwarebytesMalware.AI.2798988712
IkarusTrojan-Downloader.Win32.Autohk
FortinetW32/AHK.AAO!tr
AVGWin32:Trojan-gen

How to remove Malware.AI.2798988712?

Malware.AI.2798988712 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment