Malware

Malware.AI.3265975473 (file analysis)

Malware Removal

The Malware.AI.3265975473 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3265975473 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3265975473?


File Info:

crc32: 338DFBF7
md5: c5abfae12362337d86b77919afe16f2f
name: C5ABFAE12362337D86B77919AFE16F2F.mlw
sha1: 4a2aebe6e26916f8a0c9cba1cc9794ff1312d1f8
sha256: 24ef125669d6d252efc0f5c63067b720bcbf0e4f22dd400d5c0b8639d889ddee
sha512: e4915c74b8da9ebc278168539a37a778d79ee294a3b1c815dfc277ad688f8bc27e23fda3aed0ddc87729f3cce7fe5eb70c01cfbb3bc052bbaf12edff387aacd8
ssdeep: 12288:zN3tardhfJBYUPOLTEYbk+OWUZ1+kwJxpw4uKHnWV211u:zN383JBYUGvk+OW88bpwwx11u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: PowerCmd Software Copyright (C) 2013
InternalName: PowerCmd
FileVersion: 2.1.6.2
CompanyName: PowerCmd Software
ProductName: PowerCmd: Command Prompt Window
ProductVersion: 2.1.6.2
FileDescription: PowerCmd: Command Prompt Window
OriginalFilename: Command Prompt Window
Translation: 0x0409 0x04b0

Malware.AI.3265975473 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00420ee01 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.7639
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.A5
ALYacTrojan.Ransom.AHF
ZillyaTrojan.Blocker.Win32.21065
SangforRansom.Win32.Foreign_25.se
CrowdStrikewin/malicious_confidence_100% (W)
K7GWSpyware ( 00420ee01 )
Cybereasonmalicious.123623
CyrenW32/Backdoor.MWSO-2610
SymantecSMG.Heur!gen
ESET-NOD32Win32/Spy.Zbot.ABA
ZonerTrojan.Win32.25661
APEXMalicious
AvastWin32:GenMalicious-NI [Trj]
ClamAVWin.Trojan.Ransom-9183
KasperskyTrojan-Ransom.Win32.Blocker.fkst
BitDefenderTrojan.Ransom.AHF
NANO-AntivirusTrojan.Win32.Blocker.debwjh
SUPERAntiSpywareTrojan.Agent/Ransom-Blocker
MicroWorld-eScanTrojan.Ransom.AHF
TencentTrojan-ransom.Win32.Blocker.fkst
Ad-AwareTrojan.Ransom.AHF
SophosML/PE-A + Troj/Ransom-AKV
ComodoTrojWare.Win32.Blocker.FKS@5ek5dm
BitDefenderThetaGen:NN.ZexaF.34686.Cq0@aGrvy5gi
VIPRETrojan.Win32.Ransom.akv (v)
TrendMicroTSPY_ZBOT.SMJ41
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
FireEyeGeneric.mg.c5abfae12362337d
EmsisoftTrojan.Ransom.AHF (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.jdn
AviraTR/Spy.Zbot.sifgdlt
eGambitUnsafe.AI_Score_79%
MicrosoftPWS:Win32/Zbot
GDataTrojan.Ransom.AHF
TACHYONRansom/W32.Blocker.460288
AhnLab-V3Trojan/Win32.Zbot.R116712
Acronissuspicious
McAfeePWSZbot-FABX!C5ABFAE12362
MAXmalware (ai score=82)
VBA32Hoax.Blocker
MalwarebytesMalware.AI.3265975473
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SMJ41
RisingRansom.Blocker!8.12A (RDMK:cmRtazpsMq/Lz65BrgJ4tTXYbZHB)
YandexTrojan.Blocker!MUfPk+UzSCA
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.CJGQ!tr
AVGWin32:GenMalicious-NI [Trj]

How to remove Malware.AI.3265975473?

Malware.AI.3265975473 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment