Malware

About “Malware.AI.3065230911” infection

Malware Removal

The Malware.AI.3065230911 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3065230911 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
tb.himg.baidu.com

How to determine Malware.AI.3065230911?


File Info:

crc32: 701B21B4
md5: c366938ea91efced06eae9af108508d2
name: C366938EA91EFCED06EAE9AF108508D2.mlw
sha1: bcafdc1655b61611ff06d6b1f65df34d54c68fdc
sha256: e32c4768e442f7dde83580793b175c2fd79cd0933e8fc53d4b8637528f86b1ee
sha512: 7c3f84523436040b35594b7a333f36f59e9e5ac77e5054f351ff268ef0b13c4f6a37923610d14a4d59a782d14c17a7b5d951aac78b681c5b8194dce935e0cf9c
ssdeep: 12288:K/whdl5BMBEK/bzBjbWzSMRRc+Y6h98u1NLl46W79kzK0d3:K/QMBEK5e/c+YYXLS6W79k+
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x57fax4f6cx77edx4fe1x8f70x70b8x673a
FileVersion: 1.2.0.0
CompanyName: x65e0x6570x7684x65e0x804a
Comments: x57fax4f6cx77edx4fe1x8f70x70b8x673a
ProductName: x57fax4f6cx77edx4fe1x8f70x70b8x673a
ProductVersion: 1.2.0.0
FileDescription: x57fax4f6cx77edx4fe1x8f70x70b8x673a
Translation: 0x0804 0x04b0

Malware.AI.3065230911 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Ransom
ALYacGen:Variant.Ransom.1427
CylanceUnsafe
SangforSuspicious.Win32.Attribute.HighConfidence
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderGen:Variant.Ransom.1427
K7GWPassword-Stealer ( 004db2ff1 )
K7AntiVirusPassword-Stealer ( 004db2ff1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Ransom.1427
Ad-AwareGen:Variant.Ransom.1427
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34690.EmKfaK0UuMhb
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.c366938ea91efced
EmsisoftGen:Variant.Ransom.1427 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Zpevdo.B
ArcabitTrojan.Ransom.D593
AegisLabTrojan.Win32.Malicious.4!c
GDataGen:Variant.Ransom.1427
Acronissuspicious
McAfeeArtemis!C366938EA91E
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Netthief
MalwarebytesMalware.AI.3065230911
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazoxT6ElbnJutngULWLpEJlB)
IkarusTrojan.Win32.Scar
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
Paloaltogeneric.ml

How to remove Malware.AI.3065230911?

Malware.AI.3065230911 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment