Malware

Malware.AI.3359382089 (file analysis)

Malware Removal

The Malware.AI.3359382089 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3359382089 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
whatismyipaddress.com

How to determine Malware.AI.3359382089?


File Info:

crc32: D97BBD17
md5: 9a202a616702883f3980b58598da5b66
name: 9A202A616702883F3980B58598DA5B66.mlw
sha1: 94774bfaf37636c8729e1514786b6572c4ca38aa
sha256: bb1c496719079c2e8f2d5e87f7c5278e969fc74af3f88528bbeff04d13da6a59
sha512: 82478577a0006f814963125923ef9f417bd16d95ed9722e609a3d1807df23e9c01895da2002fe5dd103c7addced55a463ed1f1ee155a60d5ae4659ae90f0bba7
ssdeep: 12288:FmPNl9vDewRmteiy1j8e9VciiFulGxOf1MCeCrncy2bdfe0iCgYF2PSDn3oRCMqc:0PN7vCmmtxYLliF2GISCpncLpNgvPSDq
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Malware.AI.3359382089 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00527bb21 )
LionicTrojan.Win32.Blocker.j!c
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.468548
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39769
SangforTrojan.Win32.GenericKD.30355963
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Blocker.1cb8191f
K7GWTrojan ( 00527bb21 )
Cybereasonmalicious.167028
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DVZC
ZonerTrojan.Win32.67677
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packer.MalwareCrypter-6642003-1
KasperskyTrojan-Ransom.Win32.Blocker.krqh
BitDefenderGen:Variant.Graftor.468548
NANO-AntivirusTrojan.Win32.Inject.eyqfxp
MicroWorld-eScanGen:Variant.Graftor.468548
TencentWin32.Trojan.Blocker.Htbs
SophosMal/Generic-S
ComodoMalware@#1gxmo0g79vjzq
BitDefenderThetaGen:NN.ZedlaF.34796.du8@aS@wA1ei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.bc
FireEyeGen:Variant.Graftor.468548
EmsisoftGen:Variant.Graftor.468548 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1124301
MicrosoftTrojan:Win32/Detplock
ArcabitTrojan.Graftor.D72644
ZoneAlarmTrojan-Ransom.Win32.Blocker.krqh
GDataGen:Variant.Graftor.468548
AhnLab-V3Trojan/Win32.Blocker.C2440838
McAfeeArtemis!9A202A616702
MAXmalware (ai score=99)
VBA32TrojanRansom.Blocker
MalwarebytesMalware.AI.3359382089
PandaTrj/CI.A
YandexTrojan.Injector!0E+jz+B4ypk
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DVYH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HyoDEpsA

How to remove Malware.AI.3359382089?

Malware.AI.3359382089 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment