Malware

Malware.AI.3636147214 malicious file

Malware Removal

The Malware.AI.3636147214 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3636147214 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (9 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:0
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
launchermeta.mojang.com
a.tomx.xyz
x.ss2.us
o.ss2.us
ocsp.rootg2.amazontrust.com
ocsp.rootca1.amazontrust.com
launcher.mojang.com
crl.rootca1.amazontrust.com

How to determine Malware.AI.3636147214?


File Info:

crc32: EE6D03A7
md5: 2dd5a392d80f7fe89946f6fca6fd82e2
name: 2DD5A392D80F7FE89946F6FCA6FD82E2.mlw
sha1: 562a93468c5749b843cf1c14390ce5c72c3c8130
sha256: 90558effd39b3f059b67c8d66e6c23965e77c4272fd93668e2487bba885fe830
sha512: 8145dc255ff92798e6abc11d1d43ac4197b12d020a0c441403324e3c98d008c711c0ed1d3b7f91a369b21dcc7fefd0eeb48ad73e87d3ec615902799230be218c
ssdeep: 49152:xQ/d8w1KH+P1DQKVBUL9bYngTbT02rHEK1:xQ/dV1bPpBUL9s+vrHf1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.3636147214 also known as:

K7AntiVirusTrojan ( 004020ef1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Comet.152
CynetMalicious (score: 100)
CAT-QuickHealTrojan.BlockerRI.S14012074
ALYacBackdoor.Generic.755288
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/Blocker.ef8901a5
K7GWTrojan ( 004020ef1 )
Cybereasonmalicious.2d80f7
BaiduWin32.Trojan-Dropper.Agent.ca
CyrenW32/Agent.NXNL-3094
ESET-NOD32Win32/TrojanDropper.Agent.PYN
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Darkkomet-7139847-0
KasperskyTrojan-Ransom.Win32.Blocker.hrft
BitDefenderBackdoor.Generic.755288
NANO-AntivirusTrojan.Win32.Tordev.bcihzf
MicroWorld-eScanBackdoor.Generic.755288
TencentTrojan-Ransom.Win32.Blocker.a
Ad-AwareBackdoor.Generic.755288
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.pyn@54cqtm
BitDefenderThetaAI:Packer.0DFFE3EE1C
VIPRETrojan-Dropper.Win32.Effbee.a (v)
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.tc
FireEyeGeneric.mg.2dd5a392d80f7fe8
EmsisoftBackdoor.Generic.755288 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/DarkKomet.kwk
AviraTR/Patched.Ren.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.15994D
KingsoftHeur.SSC.2700553.0111.(kcloud)
MicrosoftTrojanDropper:Win32/Effbee.A
GDataWin32.Trojan-Dropper.BeiF.A
AhnLab-V3Backdoor/Win32.DarkKomet.R48242
McAfeeGenericRXAA-AA!2DD5A392D80F
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3636147214
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.100 (RDML:As0CE92tBZOQr6YOvojPPw)
YandexTrojan.GenAsa!N71EllaXIy8
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.8756622.susgen
FortinetW32/Dropper.PYN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.3636147214?

Malware.AI.3636147214 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment