Malware

What is “Malware.AI.3636136969”?

Malware Removal

The Malware.AI.3636136969 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3636136969 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3636136969?


File Info:

crc32: A00E4308
md5: ac76c86ac9e6d0fdd8605ef9afe46169
name: AC76C86AC9E6D0FDD8605EF9AFE46169.mlw
sha1: f917063f330506c8ba8bddaeeb045f38ec22806b
sha256: 6c58a8d5c3935a878d569a3e44ee31124f7a4be5f140a2eb708bd631340057f0
sha512: db6ac20e49bd81c8ae7fd51ad7e22f7a4717fbd098a9b1e2971e210b56f2e3307a1624feea759a23c50dd49ad7a8926e0421cedb14f1f6039b5b5d38f0dce5b5
ssdeep: 1536:8sBtGh7ZewCJkRA0SHMYL3XePvMOf8LZC8lrpDLb0:zMh7QwCJOA0SHLX0vMOELZRlNLb0
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: c m d
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b1

Malware.AI.3636136969 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f997d1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.MUE.A6
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2280750
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Cryptor.2bd268ac
K7GWTrojan ( 004f997d1 )
Cybereasonmalicious.ac9e6d
CyrenW32/S-ef537a26!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Cryptor.cmz
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Encoder.evjvgp
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentWin32.Trojan.Generic.Lorm
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
ComodoMalware@#39w9pdablmca6
BitDefenderThetaGen:NN.ZexaF.34170.gy0@aq0x6!bQ
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-GJA!AC76C86AC9E6
FireEyeGeneric.mg.ac76c86ac9e6d0fd
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22CC1C0
MicrosoftRansom:Win32/Tovicrypt.A
ZoneAlarmTrojan-Ransom.Win32.Cryptor.cmz
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188553
Acronissuspicious
McAfeeRansomware-GJA!AC76C86AC9E6
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.3636136969
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.100 (RDML:86BJxSWqsYsGVIKGPpQajg)
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.3636136969?

Malware.AI.3636136969 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment