Malware

Malware.AI.3676079586 removal

Malware Removal

The Malware.AI.3676079586 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3676079586 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Network anomalies occured during the analysis.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Enumerates services, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a file

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3676079586?


File Info:

crc32: A5803324
md5: 0e39598fefd02cb8178e1a99ca32b4d0
name: 0E39598FEFD02CB8178E1A99CA32B4D0.mlw
sha1: 13d5e58890c13e54160a66ed83f0557941d4d17f
sha256: 0d4de6b4b99e65ab21ab894f46091b6c8922813f56a57e72572381fa143ba144
sha512: 845974b9152b58a0c46133f1616866894b9643066a1ef737d2ccd8811f9e1c8c717ebaa1a5cc982cf5ccd337e16d7e9fed34fa9f3ee37adc05eb27ef5339c5b1
ssdeep: 24576:v1t5QUDlzr2bxU9Fz/4b6bYaBdnVE+v09OCPRIGqLUIRa:Nt5QUDBf6CVVLv0wl3Ja
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 9.1.0.0
ProductName: WinHex
FileVersion: 9.1.0.0
OriginalFilename: WINHEX.EXE
FileDescription: (c) Stefan Fleischmann, X-Ways Software
Translation: 0x0409 0x04b0

Malware.AI.3676079586 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.401217
CylanceUnsafe
ZillyaTrojan.Bingoml.Win32.6897
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Bingoml.561ae34a
Cybereasonmalicious.890c13
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Bingoml.gen
BitDefenderGen:Variant.Zusy.401217
MicroWorld-eScanGen:Variant.Zusy.401217
TencentWin32.Trojan.Bingoml.Glt
Ad-AwareGen:Variant.Zusy.401217
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WIG21
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGen:Variant.Zusy.401217
EmsisoftGen:Variant.Zusy.401217 (B)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Zusy.401217
AhnLab-V3Malware/Win.Generic.R441525
McAfeeGenericRXAA-AA!0E39598FEFD0
MAXmalware (ai score=86)
VBA32BScope.TrojanDropper.Agent
MalwarebytesMalware.AI.3676079586
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WIG21
RisingTrojan.Generic@ML.80 (RDML:M6iKD8WyLk9Jl06M7efsFw)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.109135027.susgen
FortinetW32/GenKryptik.FJOS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.3676079586?

Malware.AI.3676079586 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment