Malware

Malware.AI.3317093909 removal instruction

Malware Removal

The Malware.AI.3317093909 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3317093909 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3317093909?


File Info:

crc32: 2E3DD9FF
md5: f10945a60d4cc9f8cfcd5faffd3cfe71
name: F10945A60D4CC9F8CFCD5FAFFD3CFE71.mlw
sha1: dd69b9e2438d2fab38a492286138eb67da52dea3
sha256: 21437e562cf4b18aff394b4a75ab90dd499c2af46b41821e87bb1a6140ba157d
sha512: d90d390ed7d59df8a909f6a421bb1a5b107108d3302cc783fc98498107aa4541a9b0a4dd2a13d7591ad1315c541da841778343c0f0c446e7ace62b300b8c1481
ssdeep: 768:dCQOjto1lsrSi9SyjjN1n7nYWLqRblQwhfqYtbyH0qMrcNO+Z3/Tn:Opo18xYEjr7ARblvLw3OO3/Tn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: (C) 2012 Roblox Corporation. All rights reserved.
FileVersion: 1, 6, 3, 253053
CompanyName: Roblox Corporation
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 3, 0
FileDescription: Roblox
OriginalFilename: Roblox.exe
Translation: 0x0409 0x04b0

Malware.AI.3317093909 also known as:

K7AntiVirusTrojan ( 005254e41 )
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Wirenet.335
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AgentFC.S6060428
ALYacGen:Trojan.Mardom.MN.18
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1014506
SangforTrojan.Win32.Dropper.Gen
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 005254e41 )
Cybereasonmalicious.60d4cc
CyrenW32/MSIL_Kryptik.BVZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DNB
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Trojan.Mardom.MN.18
NANO-AntivirusTrojan.Win32.Wirenet.fjvlca
MicroWorld-eScanGen:Trojan.Mardom.MN.18
TencentWin32.Trojan.Agent.Dypl
Ad-AwareGen:Trojan.Mardom.MN.18
SophosMal/Generic-S
ComodoMalware@#1nt4cu1i1pg6d
BitDefenderThetaGen:NN.ZemsilF.34294.ap3@aiEt50kG
McAfee-GW-EditionGenericRXGN-RO!F10945A60D4C
FireEyeGeneric.mg.f10945a60d4cc9f8
EmsisoftGen:Trojan.Mardom.MN.18 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.brce
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Mardom.MN.18
GDataGen:Trojan.Mardom.MN.18
AhnLab-V3Trojan/Win32.Fuerboos.R243179
McAfeeGenericRXGN-RO!F10945A60D4C
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3317093909
PandaTrj/CI.A
YandexTrojan.Agent!1w2O0VJ4Hh8
IkarusTrojan-Dropper.MSIL.Agent
FortinetMSIL/CoinMiner.SHS!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Malware.AI.3317093909?

Malware.AI.3317093909 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment