Malware

Should I remove “Malware.AI.3443361005”?

Malware Removal

The Malware.AI.3443361005 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3443361005 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
open.baidu.com
a.tomx.xyz
www.baidu.com
ocsp.globalsign.com
www.jjfzg.com
crl.globalsign.com
ocsp2.globalsign.com
www.bing.com

How to determine Malware.AI.3443361005?


File Info:

crc32: 1E0FA017
md5: b6e9da048328cb9705d865254be5e5f2
name: B6E9DA048328CB9705D865254BE5E5F2.mlw
sha1: 992f223f5161acd4762eb4f3d53744259ae64f17
sha256: 3303c254d368d60868481742ddf903383221ae59794c5093f17bc6e39d4f2a4c
sha512: 0544a93f58b030754cfb8a573d7a944a913cb0c9a2c2782d4bd154158d2cef977bffb6935e68ed315fdadca56f60b03951a85378197847128ab68f24c52b78dd
ssdeep: 24576:lNZmx10MbLV156ODTWa63TDmrLOwFZpSygNcAZTKp4H8UWXxEJnhR3CajnjC:lNZm0Mbp15NXPEHmrHZpSygX2TUWyJnU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.3443361005 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.37078
ClamAVWin.Malware.Flystudio-9781846-0
CAT-QuickHealTrojan.MauvaiseRI.S5242799
ALYacGen:Variant.Mikey.18503
CylanceUnsafe
ZillyaTrojan.FlyStudio.Win32.15473
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
CyrenW32/S-9642dd0b!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Mikey.18503
NANO-AntivirusTrojan.Win32.TrjGen.duhkft
MicroWorld-eScanGen:Variant.Mikey.18503
TencentMalware.Win32.Gencirc.10b0d118
Ad-AwareGen:Variant.Mikey.18503
SophosGeneric PUA JJ (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34170.CnHfa09eAYkb
VIPRETrojan.Win32.OnlineGames
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.b6e9da048328cb97
EmsisoftGen:Variant.Mikey.18503 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Mikey.18503
Acronissuspicious
McAfeeArtemis!B6E9DA048328
MAXmalware (ai score=81)
VBA32BScope.Trojan.Advload
MalwarebytesMalware.AI.3443361005
IkarusTrojan-Dropper.Age
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/FlyStudio
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Malware.AI.3443361005?

Malware.AI.3443361005 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment