Malware

Malware.AI.3219840629 removal

Malware Removal

The Malware.AI.3219840629 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3219840629 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

voly.ddns.net

How to determine Malware.AI.3219840629?


File Info:

name: 7958AAB62E49C69EF8F6.mlw
path: /opt/CAPEv2/storage/binaries/db7c6c6ff312a474f8c23ebb08529cdb9863405ba2f8e9da397b31235f2a0d2a
crc32: F6FCEEA1
md5: 7958aab62e49c69ef8f64765a377788c
sha1: 8e1ee8f03f91fa179e655f68721c5c321564e8dd
sha256: db7c6c6ff312a474f8c23ebb08529cdb9863405ba2f8e9da397b31235f2a0d2a
sha512: dedb74e2ce9b2e50c67302182c992858abc714335154c0bdb68f803c574a35b49fc24edbb3e96c29e842fc175033c1d30a79bcaad481d7d2380de8f0c0fd6733
ssdeep: 3072:jxmxJTKWBBEashzJsh0hYWKoar8BBEashzJshehrJrxoVGOAJjt1csFA4at6E63C:1qVeNd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12194F53D08BF93335978C655EB488926F07285A3F1EA4F2C75D78959B10AA4378C2E3D
sha3_384: 733cbef365fcb675f1b27b3597b99ea0c6baad1ff95d9dc1ad1a3c9588fdd355fc15fc57a946489bbbd124bc12f31631
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-04-01 01:07:57

Version Info:

0: [No Data]

Malware.AI.3219840629 also known as:

LionicTrojan.MSIL.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.13678
MicroWorld-eScanTrojan.GenericKD.44840964
FireEyeGeneric.mg.7958aab62e49c69e
McAfeeRDN/Generic.hbg
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1268233
SangforTrojan.MSIL.APT-C-44.IOC
K7AntiVirusTrojan ( 0052b6481 )
AlibabaTrojan:MSIL/Kryptik.3275c9e0
K7GWTrojan ( 0052b6481 )
Cybereasonmalicious.62e49c
BitDefenderThetaGen:NN.ZemsilF.34294.zmW@aSBW0wk
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/Kryptik.NKB
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderTrojan.GenericKD.44840964
NANO-AntivirusTrojan.Win32.Bladabindi.fbefvc
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.44840964
SophosMal/Generic-S
ComodoMalware@#19l387u2qn3s3
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103JQ20
McAfee-GW-EditionBehavesLike.Win32.AdwareTskLnk.gz
EmsisoftTrojan.GenericKD.44840964 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.subq
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1122588
Antiy-AVLTrojan/Generic.ASMalwS.30FA4CD
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Generic.D2AC3804
ViRobotTrojan.Win32.S.Agent.423424.R
GDataTrojan.GenericKD.44840964
CynetMalicious (score: 100)
AhnLab-V3Trojan/Msil.RL_Generic.C3446019
Acronissuspicious
VBA32TScope.Trojan.MSIL
ALYacTrojan.MSIL.Bladabindi
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3219840629
TrendMicro-HouseCallTROJ_FRS.0NA103JQ20
TencentMsil.Trojan.Generic.Ahym
IkarusAdWare.Dotdo
FortinetMSIL/Kryptik.NKB!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.11196064.susgen

How to remove Malware.AI.3219840629?

Malware.AI.3219840629 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment