Malware

What is “Malware.AI.3648682877”?

Malware Removal

The Malware.AI.3648682877 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3648682877 virus can do?

  • Injection (inter-process)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • A potential decoy document was displayed to the user
  • Installs itself for autorun at Windows startup
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3648682877?


File Info:

crc32: EE27B4D5
md5: 48f031f8120554a5f47259666fd0ee02
name: 48F031F8120554A5F47259666FD0EE02.mlw
sha1: 02ee6302436250e1cee1e75cf452a127b397be8d
sha256: b8120d5c9c2c889b37aa9e37514a3b4964c6e41296be216b327cdccd2e908311
sha512: f49fc9d647ff5b2e033dd442d83aa7222df42fb3a6d89716461ac101c9ec819f4de5047f09ab57cf803ba9ad6d88b03165148127dfe19e7771f38533ddb56581
ssdeep: 12288:5Xw0rs03DI8HSmkU1oU6denDbUbYGCnCdibvTZtk/7i+:5XJD3FbkUKUKe7GCCdKtK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.3648682877 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005251f51 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.4404
CynetMalicious (score: 99)
CAT-QuickHealTrojan.MauvaiseRI.S5256027
ALYacTrojan.Agent.Nokki
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.08c30a66
K7GWTrojan ( 005251f51 )
Cybereasonmalicious.812055
SymantecBackdoor.Tinybaron
ESET-NOD32Win32/Spy.Virkonni.O
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.kqsf
BitDefenderGen:Heur.Bodegun.1
NANO-AntivirusTrojan.Win32.Bodegun.eyizip
ViRobotDropper.Agent.551936
MicroWorld-eScanGen:Heur.Bodegun.1
TencentWin32.Trojan.Blocker.Pgmy
Ad-AwareGen:Heur.Bodegun.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34796.du0@aaT9Wcgi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.MSIL.BERBOMTHUM.AA.tmsr
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.48f031f8120554a5
EmsisoftGen:Heur.Bodegun.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.igu
WebrootW32.Gen.BT
AviraTR/Dldr.Agent.juigr
Antiy-AVLTrojan/Generic.ASMalwS.310970F
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Blocker
GDataGen:Heur.Bodegun.1
AhnLab-V3Dropper/Win32.Agent.R238194
McAfeeTrojan-FQEM!48F031F81205
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agentb
MalwarebytesMalware.AI.3648682877
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.MSIL.BERBOMTHUM.AA.tmsr
RisingTrojan.Generic@ML.100 (RDML:U6QcaPPZv1BfDjJPSIqEYw)
YandexTrojan.DL.Agent!0BNOeiU610E
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.77521138.susgen
FortinetW32/Agent.ZKQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOoA

How to remove Malware.AI.3648682877?

Malware.AI.3648682877 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment