Malware

Should I remove “Malware.AI.2992958935”?

Malware Removal

The Malware.AI.2992958935 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2992958935 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
buterin-vitalik.fun

How to determine Malware.AI.2992958935?


File Info:

crc32: CC15AB99
md5: 6b37bdfdca5ef113a6ce13c39d3397cd
name: 6B37BDFDCA5EF113A6CE13C39D3397CD.mlw
sha1: 7b2c02401113c5e8dbfe5b2b7159197f3c3f8f6f
sha256: 4c9f6f70f5d51d77bdbc5148781689e72f62a9eeba8205daafaba315194d132e
sha512: cbda96c079ff48c4ede4d9c5ff3bee2b475457be4eab6e0914127b80b5235a41bc83334869c36727159d8ed8c42373900e5097b47154f229273fc66b9a019c6d
ssdeep: 3072:AnmxTzp5LbXPFf0F5ELSZWgwoHQ3AfzR4IcdqyNQT6wWTz+BNlR6:Am5p5R0FCqWGQQV4TdqgQQTG16
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2992958935 also known as:

K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24300
ClamAVWin.Ransomware.GandCrab-9843250-0
ALYacDeepScan:Generic.BrResMon.1.909E2C4E
ZillyaTrojan.GenericKD.Win32.145070
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaVirTool:Win32/CeeInject.4abb4c62
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.dca5ef
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GJRH
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.gen
BitDefenderDeepScan:Generic.BrResMon.1.909E2C4E
NANO-AntivirusTrojan.Win32.Coins.fhvzvl
MicroWorld-eScanDeepScan:Generic.BrResMon.1.909E2C4E
TencentWin32.Trojan.Generic.Wozv
Ad-AwareDeepScan:Generic.BrResMon.1.909E2C4E
SophosML/PE-A
ComodoTrojWare.Win32.Ransom.GandCrypt.GL@7shqx0
BitDefenderThetaGen:NN.ZexaF.34690.nuW@aqNu7YlG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.6b37bdfdca5ef113
EmsisoftDeepScan:Generic.BrResMon.1.909E2C4E (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Coins.amr
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1119074
MicrosoftVirTool:Win32/CeeInject.UN!bit
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.gen
GDataDeepScan:Generic.BrResMon.1.909E2C4E
AhnLab-V3Win-Trojan/Gandcrab06.Exp
Acronissuspicious
McAfeeTrojan-FPYT!6B37BDFDCA5E
VBA32BScope.Trojan.Vigorf
MalwarebytesMalware.AI.2992958935
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B3B1 (CLOUD)
YandexTrojan.GenAsa!5YoSyCDNWRs
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CHXK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2992958935?

Malware.AI.2992958935 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment