Malware

Malware.AI.3422691327 removal instruction

Malware Removal

The Malware.AI.3422691327 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3422691327 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Nymaim malware
  • Checks the version of Bios, possibly for anti-virtualization
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system

Related domains:

haqgcyzzrhyr.com
zbbmvgh.pw
ytlbpbx.pw
bwaxqcmrtt.com
pxnwtuxo.in
iwfbmdvftib.in
zzliuvhql.pw
opocob.pw
lcbijis.com
ngsqymfv.com
aaslu.pw
tjrcewdd.net
jwhjluugqzga.net
fsduv.net
kojntkaldbiv.com

How to determine Malware.AI.3422691327?


File Info:

crc32: F29AA1B7
md5: ff6d4fb597f02c8f18c9735db91ae87a
name: FF6D4FB597F02C8F18C9735DB91AE87A.mlw
sha1: b4d419a6233115785313712b37d272bdb53b8b11
sha256: f89bbfce5635184cefce7e5be91bdde2c85aa0d6cb5f6585c1c1e771df180530
sha512: 77bfcdf2c0b73ac6fc4540eef6631a6db9be6790e32a20281c4995f5198893ef0c8f2e8061632160ab727cede56f412483b9cfbae6ef8a668267da0211bf46f6
ssdeep: 12288:20K2pNuxvwrop5vhnOuOsaTartsjzkd0NyX7eX4fMbXdYKj:20mvbNLZaT1jzkd0NyX7eX4fCNdj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2016 Back To Basics Chiropractic Clinic nor
InternalName: BackToBasicsChiropracticClinicTheHappyBear.exe
FileVersion: 7.46.4.464
CompanyName: Back To Basics Chiropractic Clinic nor
LegalTrademarks: Back To Basics Chiropractic Clinic nor
ProductName: Back To Basics Chiropractic Clinic The Happy Bear
ProductVersion: 3,88,4,4
FileDescription: Back To Basics Chiropractic Clinic The Happy Bear
OriginalFilename: BackToBasicsChiropracticClinicTheHappyBear.exe
Translation: 0x0409 0x04b0

Malware.AI.3422691327 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CIPY
FireEyeGeneric.mg.ff6d4fb597f02c8f
ALYacTrojan.Agent.CIPY
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00511e9b1 )
BitDefenderTrojan.Agent.CIPY
K7GWTrojan ( 00511e9b1 )
Cybereasonmalicious.597f02
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.eqmaer
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.Agent.CIPY
EmsisoftTrojan.Agent.CIPY (B)
ComodoTrojWare.Win32.Agent.CISL@75bthk
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.Inject2.55006
TrendMicroTROJ_KRYPTIK_GG310537.UVPM
McAfee-GW-EditionTrojan-FNJV!FF6D4FB597F0
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
JiangminTrojan.Generic.bmabd
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.Regsup
MicrosoftTrojanDownloader:Win32/Silcon!rfn
ArcabitTrojan.Agent.CIPY
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Packed.Kryptik.HD
AhnLab-V3Trojan/Win32.Regsup.C2035184
Acronissuspicious
McAfeeTrojan-FNJV!FF6D4FB597F0
MAXmalware (ai score=82)
VBA32Trojan.Regsup
MalwarebytesMalware.AI.3422691327
PandaTrj/Matsnu.B
ESET-NOD32a variant of Win32/Kryptik.FTWH
TrendMicro-HouseCallTROJ_KRYPTIK_GG310537.UVPM
TencentMalware.Win32.Gencirc.10b5ba41
YandexTrojan.Kryptik!ChMYNrg/7jU
SentinelOneStatic AI – Malicious PE
FortinetW32/Nymaim.BG!tr
BitDefenderThetaGen:NN.ZexaF.34804.Pq0@aSIIVsoe
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.a96

How to remove Malware.AI.3422691327?

Malware.AI.3422691327 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment