Malware

Malware.AI.3672421647 removal instruction

Malware Removal

The Malware.AI.3672421647 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3672421647 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

abujafirms.com
yokiri.com

How to determine Malware.AI.3672421647?


File Info:

crc32: D274555F
md5: 9015731ca9e9353ed805e152d8db93e0
name: 9015731CA9E9353ED805E152D8DB93E0.mlw
sha1: e7af36667a58ebaf9bb819f7f805dc43e064a1cc
sha256: 741d2ee90c0a5d1858aff67392f020db9b4fad2c958c6698c085f2e1cd4a0b86
sha512: f308e0345dce92b24de07eb67eed36116bd5bc7480a47a990b32f29a2a6f3501b284aedf9c71e9ec63496f5ddf5e9612e47d0080b983ca4f5e896b23b0cc74c1
ssdeep: 12288:BYorbuuxJRMD1I77LmMk8gLQb6b9nE8FZWxAMFiMo2uSG+jk:RrBBMD1I7mfFLo8/WxAyx2+k
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa92005-2015 J-Paul Mesnage & AutoIt Team
InternalName: AutoIt3Help
FileVersion: 1.0.0.8
CompanyName: AutoIt Team
Comments: https://www.autoitscript.com/site/autoit/
ProductName: AutoIt3Help
ProductVersion: 1.0.0.8
FileDescription: AutoIt3Help viewer
OriginalFilename: AutoIt3Help.exe
Translation: 0x0809 0x04b0

Malware.AI.3672421647 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005689e31 )
LionicTrojan.Win32.Kryptik.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.46567
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S14880257
ALYacGen:Variant.Graftor.775267
ZillyaTrojan.Injector.Win32.748864
SangforTrojan.Win32.Kryptik.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/FormBook.f3dd3c53
K7GWTrojan ( 005689e31 )
Cybereasonmalicious.ca9e93
CyrenW32/Trojan.MRPX-5904
SymantecInfostealer.Lokibot!43
ESET-NOD32a variant of Win32/Injector.ELLC
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Dropper.Remcos-9235860-0
KasperskyHEUR:Trojan.Win32.Kryptik.gen
BitDefenderGen:Variant.Graftor.775267
NANO-AntivirusTrojan.Win32.TrjGen.hilhfe
MicroWorld-eScanGen:Variant.Graftor.775267
TencentMalware.Win32.Gencirc.10cdddbd
Ad-AwareGen:Variant.Graftor.775267
SophosMal/Generic-S
ComodoMalware@#2wmtna8ort2z6
BitDefenderThetaGen:NN.ZelphiF.34236.JmKfaOvV9Spi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FCOR!9015731CA9E9
FireEyeGeneric.mg.9015731ca9e9353e
EmsisoftGen:Variant.Graftor.775267 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Kryptik.bet
AviraTR/Injector.ezyts
Antiy-AVLTrojan/Generic.ASMalwS.30382C3
MicrosoftTrojan:Win32/FormBook.BX!MTB
ArcabitTrojan.Graftor.DBD463
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataGen:Variant.Graftor.775267
AhnLab-V3Malware/Win.Win.R428499
McAfeePWS-FCOR!9015731CA9E9
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.3672421647
PandaTrj/GdSda.A
RisingTrojan.Injector!1.C561 (CLASSIC)
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ELKP!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.3672421647?

Malware.AI.3672421647 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment