Categories: Malware

About “Malware.AI.3082091981” infection

The Malware.AI.3082091981 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3082091981 virus can do?

  • Executable code extraction
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Malware.AI.3082091981?


File Info:

crc32: CD803E02md5: cfb94a7d7cd3e318116583e82ac1ddc5name: CFB94A7D7CD3E318116583E82AC1DDC5.mlwsha1: 2dfe6d97d6e765ae383fc1b07dbdffa815f2599asha256: 2cb4f25bdcd46ef4c65f274388eceee13c74b20ba7e21a597c06c9cc05a4f5dbsha512: 56992941be7928f747b6fd7114576cef0dd24a9bf0e96ecee09e68d000063aed0fcf9aafe440c4bd6d6967065aa75d300dc1a127354ce6cf23ce79fea7c36f32ssdeep: 1536:/eYBhXq+cjGBHdksHzofZxtRMPxPzMzuEjd9Y6C66ildqKslndCej3HrS:mY8OBzK4pQz9NzanIej3LStype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0InternalName: YRbLFileVersion: 6.15.0004CompanyName: VpGlwnD YKO Q7cbpXSwVyMX0oComments: HGo0L BurPu FgW7HProductName: HGo0L BurPu FgW7HProductVersion: 6.15.0004FileDescription: LW8aR RZPj D8MJlwRhOriginalFilename: YRbL.exe

Malware.AI.3082091981 also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus NetWorm ( 700000151 )
Lionic Trojan.Win32.VBKrypt.4!c
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
Cylance Unsafe
Zillya Trojan.Injector.Win32.417222
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Trojan:Win32/VBKrypt.64376998
K7GW NetWorm ( 700000151 )
Cybereason malicious.7d6e76
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Injector.SIB
APEX Malicious
Avast Win32:Kolab-ZW [Trj]
Kaspersky Trojan.Win32.VBKrypt.pinb
NANO-Antivirus Trojan.Win32.Inject.uqixt
Tencent Win32.Trojan.Vbkrypt.Tdft
Sophos ML/PE-A + Mal/VBCheMan-C
Comodo Malware@#316y55dnnaxbg
BitDefenderTheta AI:Packer.1D0DBF3F20
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.cc
FireEye Generic.mg.cfb94a7d7cd3e318
SentinelOne Static AI – Malicious PE
Jiangmin Trojan/Vilsel.aend
Webroot W32.Malware.Gen
Avira TR/Dropper.Gen
eGambit Generic.Dropper
Antiy-AVL Trojan/Generic.ASMalwS.162930B
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Trojan/Win32.VBKrypt.R27865
McAfee Artemis!CFB94A7D7CD3
MAX malware (ai score=100)
Malwarebytes Malware.AI.3082091981
Panda Generic Malware
Ikarus Trojan.Win32.Spy
Fortinet W32/Jorik_Steckt.N!tr
AVG Win32:Kolab-ZW [Trj]

How to remove Malware.AI.3082091981?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Win32/Kryptik.XFZ information

The Win32/Kryptik.XFZ is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

How to remove “Trojan:Win32/Cendelf!pz”?

The Trojan:Win32/Cendelf!pz is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Should I remove “Fugrafa.30711”?

The Fugrafa.30711 is considered dangerous by lots of security experts. When this infection is active,…

23 mins ago

Malware.AI.1251652225 information

The Malware.AI.1251652225 is considered dangerous by lots of security experts. When this infection is active,…

37 mins ago

Trojan.Generic.35803163 (file analysis)

The Trojan.Generic.35803163 is considered dangerous by lots of security experts. When this infection is active,…

57 mins ago

What is “Jaik.220995”?

The Jaik.220995 is considered dangerous by lots of security experts. When this infection is active,…

57 mins ago