Malware

How to remove “Malware.AI.3416346225”?

Malware Removal

The Malware.AI.3416346225 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3416346225 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.ip138.com
tj.jdlook.com
dwonload.sz-qudou.net

How to determine Malware.AI.3416346225?


File Info:

crc32: 81FC2314
md5: bf9bdc9555b5ba89b4a17641dbac68ea
name: BF9BDC9555B5BA89B4A17641DBAC68EA.mlw
sha1: 6ccedfdd4d460a8d6e2734d49458e01dc7f83db8
sha256: 238b28ff3d423fb3d1cc3df0a8c663b1433eea4cb7c12912b5494cc2580e75de
sha512: fffc5580efbf49517fd9d9c7b74849b841e03fe1e4b56461edf4eeab36a1ea6167f1c83abe16e7757d06e48f4b753b5e83a197eaaf682f7d87c99b9abd4365a0
ssdeep: 24576:EXle6icxeTycrB5Y23AVpgvBUxJN530O42+Qj3Ssl3WO3LfOtPmnJfHahy8BHHAS:An9xeTycbY23W990z2+YpjiP2f6VBHHJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x6781x901fx4e0bx8f7dx5668
CompanyName: x6781x901fx4e0bx8f7dx5668
ProductName: x6781x901fx4e0bx8f7dx5668
ProductVersion: 1,2,3,18908
FileDescription: x6781x901fx4e0bx8f7dx5668
OriginalFilename: Setup.exe
Translation: 0x0804 0x04b0

Malware.AI.3416346225 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 0053e9eb1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.6939
CynetMalicious (score: 100)
CAT-QuickHealPUA.Bundler.S3936668
CylanceUnsafe
K7GWAdware ( 0053e9eb1 )
Cybereasonmalicious.d4d460
CyrenW32/S-623a050e!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.AN potentially unwanted
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Malware.Softcnapp-6940714-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Mlw.fipbtx
TencentMalware.Win32.Gencirc.10b3fcda
SophosMal/Generic-S
ComodoApplication.Win32.AdWare.Softcnapp.H@7x5l7p
BitDefenderThetaGen:NN.ZexaF.34294.Tz3@aOoKVBhj
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.bf9bdc9555b5ba89
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cqjhm
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.282B0EF
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
Acronissuspicious
McAfeeGenericRXGO-EO!BF9BDC9555B5
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.3416346225
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.100 (RDML:gbt2/AvqJekq7WnV6uSRVw)
YandexTrojan.GenAsa!T2hgklBBNow
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Symmi.CD14!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.3416346225?

Malware.AI.3416346225 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment