Malware

Malware.AI.3242361281 malicious file

Malware Removal

The Malware.AI.3242361281 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3242361281 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Steals private information from local Internet browsers
  • Attempts to identify installed AV products by installation directory
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkip.dyndns.org
freegeoip.app

How to determine Malware.AI.3242361281?


File Info:

crc32: 83CA269B
md5: 325fb848ba8b93295817fff534bd1a75
name: 325FB848BA8B93295817FFF534BD1A75.mlw
sha1: f5458acc18d903da74b5f38da4be91f50d9ffe29
sha256: ad34fe380bb9d7aca419a4da6729eb22cfc64f3003bda67acc3267cdc4ccdb21
sha512: 64adddcab4924c259965dd3ab63d599ae6f6ea713d56a746ef294bffa7398b387d54902cbd7449d2ca1e90572252f33c7348c4b4b549defb9da4f04e4950f012
ssdeep: 12288:pig98EJXfXUynYURmNX8afLesVLJKMkPKqjeTfhf4phj+Q+JzlmaH0bDZ5FncWd:pig9VU6mDLB0om2C7TK9HIt5FcsD
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2015
Assembly Version: 1.0.0.0
InternalName: rmhQPCz.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
LegalTrademarks:
Comments:
ProductName: stuSys
ProductVersion: 1.0.0.0
FileDescription: stuSys
OriginalFilename: rmhQPCz.exe

Malware.AI.3242361281 also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Bulz.584517
CyrenW32/MSIL_Kryptik.EZZ.gen!Eldorado
SymantecScr.Malcode!gdn30
ESET-NOD32a variant of MSIL/Kryptik.ACEU
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
MicroWorld-eScanGen:Variant.Bulz.584517
Ad-AwareGen:Variant.Bulz.584517
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34050.7m0@a0Xu5Ie
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
FireEyeGeneric.mg.325fb848ba8b9329
EmsisoftGen:Variant.Bulz.584517 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Bulz.D8EB45
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Bulz.584517
MAXmalware (ai score=86)
VBA32CIL.HeapOverride.Heur
MalwarebytesMalware.AI.3242361281
MaxSecureTrojan.Malware.300983.susgen
Paloaltogeneric.ml

How to remove Malware.AI.3242361281?

Malware.AI.3242361281 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment