Malware

Malware.AI.3208348814 removal instruction

Malware Removal

The Malware.AI.3208348814 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3208348814 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Malware.AI.3208348814?


File Info:

crc32: CEFCD8CD
md5: dbd985e9c500ca191ad1b764235444ed
name: DBD985E9C500CA191AD1B764235444ED.mlw
sha1: 97bc7a4d64d37871b11d39bbfad250fb5433e9b4
sha256: 0665ec13ec3e45f3f50582d28cdaad4dbce2f5dc9e3e67aa323003dd82d8d0d7
sha512: 4d23a938622870fd88e174d89adc8069c293e01aadd8d6385c092fbabb3f73b43cab41ebdd2fecc42cdfb8bac2cf819fb4aff895fb08017d5c0d54bd2d0c277f
ssdeep: 6144:qbhVtZsJage46g4YsiB3P5plDHDerwxImRo6g6x2:qVVtyY9/YsiVPLBHDekxII
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2006-2010 Christian Ghisler
InternalName: Totalcmd-Admin
FileVersion: 1, 0, 0, 5
CompanyName: Ghisler Software GmbH
sler Software GmbH Totalcmd-Admin: :x0bx01ProductVersion
ecialBuild: D
ivateBuild: j%x01ProductName
LegalTrademarks: Nx13x01OriginalFilename
alcmd-Admin.exe:
Comments: Tool used internally by Total Commander, do not start directly!
FileDescription: Total Commander Administrator Tool
0, 0, 5:
Translation: 0x0409 0x0000

Malware.AI.3208348814 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Ransom.Win32.1180
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.c3f72066
K7GWTrojan ( 005224381 )
Cybereasonmalicious.9c500c
BaiduWin32.Trojan.Kryptik.awu
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FKVG
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Kryptik.evlukm
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentMalware.Win32.Gencirc.11494e56
Ad-AwareTrojan.Ransom.Cerber.1
SophosMal/Generic-R + Mal/Ransom-EJ
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34790.oq0@aO@0Foq
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCERBER.SM3
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.dbd985e9c500ca19
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22D8BDB
MicrosoftRansom:Win32/Avaddon.P!MSR
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Lukitus2.Exp
Acronissuspicious
McAfeeTrojan-FORL!DBD985E9C500
MAXmalware (ai score=100)
VBA32BScope.TrojanProxy.Bunitu
MalwarebytesMalware.AI.3208348814
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM3
RisingTrojan.Kryptik!1.AE9C (CLASSIC)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dridex.DD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBEpsA

How to remove Malware.AI.3208348814?

Malware.AI.3208348814 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment