Malware

What is “Malware.AI.3541738483”?

Malware Removal

The Malware.AI.3541738483 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3541738483 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:8888
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

www.bing.com
www.9170.org

How to determine Malware.AI.3541738483?


File Info:

crc32: 4906AFB8
md5: e966f0eaa2383e906e5ce6563bfffd0e
name: E966F0EAA2383E906E5CE6563BFFFD0E.mlw
sha1: b86837ce4e33038aebddd5ec0277bceeaf6696db
sha256: d6990fd6364772a3d7f871c088d68e1f8e07bbe5dfb458c3f105aa42c3f318b4
sha512: 298933cb32163cff35851600d0c1d0d7ec5252dd0c81c8651082d1f06ddaed5d527977318c49bbab6da45f5a67c4cfa3433555a6b2ee4ea668742c53c8aec58e
ssdeep: 12288:OwqDtX26/TxzxwdBmv0KIKQNAcOdsR/zRoMuf:gDdTxQExIKQ9OdsZtE
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.3541738483 also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Multi.Generic.lmpu
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.e4e330
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
AvastFileRepMalware
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Frethoq.cyoysn
ViRobotTrojan.Win32.Z.Frethoq.512512
SophosGeneric PUA LI (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34170.FmGfa0DlY2aH
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.hc
FireEyeGeneric.mg.e966f0eaa2383e90
SentinelOneStatic AI – Malicious PE
eGambitHackTool.Generic
Antiy-AVLTrojan/Generic.ASMalwS.66EF91
KingsoftWin32.Troj.Agent.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.19Q2126
Acronissuspicious
McAfeeArtemis!E966F0EAA238
MAXmalware (ai score=98)
VBA32TrojanPSW.Frethoq
MalwarebytesMalware.AI.3541738483
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R067H0CIT21
IkarusTrojan-GameThief.Win32.Frethoq
FortinetW32/Frethoq.FAKL!tr
AVGFileRepMalware

How to remove Malware.AI.3541738483?

Malware.AI.3541738483 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment