Malware

Malware.AI.3156476198 information

Malware Removal

The Malware.AI.3156476198 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3156476198 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Finnish
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.maxmind.com
a.tomx.xyz

How to determine Malware.AI.3156476198?


File Info:

crc32: A18C4D74
md5: a39782b2428b76be47cef2ef8447ac3b
name: A39782B2428B76BE47CEF2EF8447AC3B.mlw
sha1: c131f981836608c2ba99b5a60793809a77e79d08
sha256: 046275ea26ae9d537d4517e6b5e1160c35e5940e5de07fffa98cd0615de0953d
sha512: b8761741bd5eb6ca069a1ed401b756234b895c8e4983efa09346e34f603757772ddf08408155b5afa3d81523a3a6b1724a0882b7d4b64d1363a02a9355ee8d11
ssdeep: 768:kw2I1Ko8Qrle8MuFJ7KPHf/E+TVNuq2twCcBLAN6wDWQVlI/SrM/dr0CjbxMXhF:RUHnE+TVNuQ2tKQVrM/d4M9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.3156476198 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusP2PWorm ( 004cb9941 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.63780
CynetMalicious (score: 100)
CAT-QuickHealTrojan.FsysnaVMF.S22457391
ALYacGen:Variant.Midie.97058
CylanceUnsafe
ZillyaTrojan.VBKrypt.Win32.82583
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWP2PWorm ( 004cb9941 )
Cybereasonmalicious.2428b7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.KLF
APEXMalicious
AvastWin32:GenMalicious-KJJ [Trj]
ClamAVWin.Trojan.Vbkrypt-20605
KasperskyTrojan.Win32.Fsysna.anmj
BitDefenderGen:Variant.Midie.97058
NANO-AntivirusTrojan.Win32.VBKrypt.bfobuk
ViRobotTrojan.Win32.A.VBKrypt.69634.A
MicroWorld-eScanGen:Variant.Midie.97058
TencentMalware.Win32.Gencirc.10cebe78
Ad-AwareGen:Variant.Midie.97058
SophosMal/Generic-S
ComodoMalware@#e2wcy4ua492w
BitDefenderThetaGen:NN.ZevbaF.34170.emX@aO@PcaoG
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.10HF13
McAfee-GW-EditionBehavesLike.Win32.Packed.kh
FireEyeGeneric.mg.a39782b2428b76be
EmsisoftGen:Variant.Midie.97058 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/VBKrypt.hcyh
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.21FAF2
KingsoftWin32.Troj.VBKrypt.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Midie.D17B22
GDataGen:Variant.Midie.97058
AhnLab-V3Trojan/Win32.VBKrypt.R102564
McAfeeGenericRXPJ-CP!A39782B2428B
MAXmalware (ai score=81)
VBA32BScope.TrojanClicker.Dopa
MalwarebytesMalware.AI.3156476198
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.10HF13
YandexTrojan.GenAsa!xlw6OSpkxBM
IkarusTrojan.Win32.Swisyn
MaxSecureTrojan.Malware.2200101.susgen
FortinetW32/VBInjector.W!tr
AVGWin32:GenMalicious-KJJ [Trj]

How to remove Malware.AI.3156476198?

Malware.AI.3156476198 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment