Malware

What is “Malware.AI.3616357514”?

Malware Removal

The Malware.AI.3616357514 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3616357514 virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3616357514?


File Info:

crc32: C55C19C4
md5: fe3374da806cf3f5c4e95d104641f88c
name: FE3374DA806CF3F5C4E95D104641F88C.mlw
sha1: 964a57b0b98cd8f13da78495dffbeb290a7bef30
sha256: ac2f6be5e15c9c9344043219d8487fdbe92ad443fa23b195b4f4baee5500a5f9
sha512: 20b68325ff3bccc3266a974b087657e7e32858bc832dca4f03e43964d0f612ba65e4a3289be8bdca6d67b14479383a400031fe0dae599849b368d8bceca94772
ssdeep: 49152:4kwkn9IMHeaP983vusJbd0NXwvPuQaPCS:DdnV+3vv0cuPPC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.3616357514 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacAIT:Trojan.Nymeria.4170
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 700000111 )
K7AntiVirusTrojan ( 700000111 )
CyrenW32/AutoIt.SM.gen!Eldorado
ESET-NOD32a variant of Win32/PSWTool.MailPassView.E potentially unsafe
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Malware.Autoit-9780500-0
Kasperskynot-a-virus:HEUR:PSWTool.Win32.NetPass.gen
BitDefenderAIT:Trojan.Nymeria.4170
MicroWorld-eScanAIT:Trojan.Nymeria.4170
Ad-AwareAIT:Trojan.Nymeria.4170
SophosGeneric PUA JG (PUA)
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.fe3374da806cf3f5
EmsisoftAIT:Trojan.Nymeria.4170 (B)
AviraDR/AutoIt.Gen8
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataAIT:Trojan.Nymeria.4170 (2x)
AhnLab-V3Malware/Win32.Generic.C4192480
McAfeeArtemis!FE3374DA806C
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3616357514
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Agent.OZU!tr
AVGFileRepMetagen [Malware]

How to remove Malware.AI.3616357514?

Malware.AI.3616357514 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment