Malware

Malware.AI.3156691918 malicious file

Malware Removal

The Malware.AI.3156691918 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3156691918 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Malware.AI.3156691918?


File Info:

crc32: 021BFAE4
md5: 84ab0c2b10006c87b8518f8d9084b067
name: 84AB0C2B10006C87B8518F8D9084B067.mlw
sha1: 387ffc10d6dd4e776b4a1a8ac030db9798635d55
sha256: e84521d881b5ce38a6722ae06a694ad1782746283e62d5a2dfb6e5e79cc121a9
sha512: c899d6292ef0a48fd55fe17ae643f0d6144a3fe76cdae2ff7b9b2d418ca9c073978fe239edbb590083cce0cc2a15ba136afd3f536e69eeb3c32ef12d974f1656
ssdeep: 3072:EobpjNav9uF06wwI2j0L2CV26FmDizrvHQTULz0oL:Eobps9S06ww/YL2CV264AdL
type: MS-DOS executable, MZ for MS-DOS

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Malware.AI.3156691918 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
FireEyeGeneric.mg.84ab0c2b10006c87
Qihoo-360HEUR/QVM19.1.A4F0.Malware.Gen
McAfeeRDN/Ransom
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderGen:Variant.Ransom.CryptXXX.1
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.b10006
BitDefenderThetaGen:NN.ZexaF.34590.hq0@aaQHyQaQ
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazrFrsnidR2dP/czVg/zKQcl)
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen3
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
IkarusPacker.Win32.Krap
JiangminTrojan.Generic.brwmb
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Ransom.CryptXXX.1
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Ransom.CryptXXX.1
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4351323
Acronissuspicious
VBA32BScope.Trojan.Bagsu
ALYacGen:Variant.Ransom.CryptXXX.1
MAXmalware (ai score=80)
MalwarebytesMalware.AI.3156691918
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HGEN
YandexTrojan.GenAsa!fV4lYBUPwBQ
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3156691918?

Malware.AI.3156691918 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment