Malware

What is “Malware.AI.3358199107”?

Malware Removal

The Malware.AI.3358199107 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3358199107 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz
r3—sn-4g5e6nzz.gvt1.com
update.googleapis.com

How to determine Malware.AI.3358199107?


File Info:

crc32: 2E05ABF0
md5: 8f96ab46a0be45d68388cc02c8f0e18d
name: 8F96AB46A0BE45D68388CC02C8F0E18D.mlw
sha1: 5f4efe013409e483b0d98d5d913f5ca22c609301
sha256: 2643fbabf67dfe0de347951a8586a6d945610cb7ee4cacd27c4b83be93aba301
sha512: 2e200ffeecdd6e7ab3c78788c9f81b6a6c07ba20e2096bb27d62b47ba34fd0da9bdf21a2c72493c79e702fe8c934d379a4bc53e93c4ca6a296797073b57d637e
ssdeep: 24576:Ztb20pkaCqT5TBWgNQ7aa1ZBkSBkTR0JFBHN0f45tyi1PwjRkC6A:qVg5tQ7aEZBET2xN0fKtT1Pk5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.3358199107 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CAT-QuickHealTrojanPWS.AutoIT.Dclog.S
McAfeeTrojan-AitInject.ar
CylanceUnsafe
Cybereasonmalicious.6a0be4
ArcabitAIT:Trojan.GenericTKA.48
BaiduAutoIt.Trojan.Injector.d
CyrenW32/AutoIt.QE.gen!Eldorado
APEXMalicious
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Script.Generic
BitDefenderAIT:Trojan.GenericTKA.48
NANO-AntivirusTrojan.Script.AutoIt.estdtw
MicroWorld-eScanAIT:Trojan.GenericTKA.48
RisingTrojan.Injector/Autoit!1.C5B5 (CLASSIC)
Ad-AwareAIT:Trojan.GenericTKA.48
EmsisoftAIT:Trojan.GenericTKA.48 (B)
F-SecureHeuristic.HEUR/AGEN.1100057
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.8f96ab46a0be45d6
SophosML/PE-A + Troj/Autoit-BSC
AviraHEUR/AGEN.1100057
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Predator!ml
ZoneAlarmHEUR:Trojan.Script.Generic
GDataAIT:Trojan.GenericTKA.48 (2x)
BitDefenderThetaAI:Packer.6A29D41418
ALYacAIT:Trojan.GenericTKA.48
MalwarebytesMalware.AI.3358199107
ESET-NOD32a variant of Win32/Injector.Autoit.BKC
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_83%
FortinetW32/Autoit.BKC!tr
AVGScript:SNH-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3358199107?

Malware.AI.3358199107 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment