Malware

How to remove “Malware.AI.3676361923”?

Malware Removal

The Malware.AI.3676361923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3676361923 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3676361923?


File Info:

crc32: 62AC9B67
md5: dd909d4f26125a87a99a556c64295286
name: DD909D4F26125A87A99A556C64295286.mlw
sha1: e83c11f66358eaa3c0ce615d40d7f0634e63eca9
sha256: 6522cfdae7fc404c14d94d88c2ae1f3207399d181828ca55e541d856fd78163d
sha512: 1490a2c32eb2649ab26eb8438ad56bb95b9736ec13dbb75117d42ab4193fdab0e1c0588407102dca4477a27e27605a9e1b3e22bdc2b319f4749b636acff3304b
ssdeep: 3072:X+l80Yz8d3JjX/ciMK/XBuZcoVCc9/ttC9wryGl:ul+KlX0iXoQUtY9fc
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Microsoft Corporation
InternalName: kernelsNT
FileVersion: 3.00
CompanyName: Microsoft Corporation
LegalTrademarks: Microsoft Corporation
Comments: kernelNT
ProductName: kernelNT
ProductVersion: 3.00
FileDescription: kernelNT.exe
OriginalFilename: kernelsNT.exe

Malware.AI.3676361923 also known as:

K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Bancos.207
ClamAVWin.Spyware.Banker-201
CMCGeneric.Win32.dd909d4f26!MD
ALYacDropped:Trojan.Banker.VB.AB
CylanceUnsafe
SangforTrojan.Win32.Banker.AB
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanSpy:Win32/Bancos.1afa17ad
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.f26125
CyrenW32/Bancos.DQCQ-2179
SymantecInfostealer.Bancos
ESET-NOD32Win32/Spy.Bancos.U
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.Bancos.ha
BitDefenderDropped:Trojan.Banker.VB.AB
NANO-AntivirusTrojan.Win32.Banker.eprp
MicroWorld-eScanDropped:Trojan.Banker.VB.AB
TencentMalware.Win32.Gencirc.10b5475f
Ad-AwareDropped:Trojan.Banker.VB.AB
SophosML/PE-A + Troj/Bancos-RO
ComodoTrojWare.Win32.Spy.Bancos.ha_dam0@1n5j4q
BitDefenderThetaGen:NN.ZevbaF.34690.hi0faa2wgTei
VIPRETrojan-Spy.Win32.Bancos.ha (v)
TrendMicroTSPY_BANCOS.BAD
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.dd909d4f26125a87
EmsisoftDropped:Trojan.Banker.VB.AB (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Bancos.bse
AviraTR/Spy.Bancos.ha.dam
MicrosoftTrojanSpy:Win32/Bancos
ArcabitTrojan.Banker.VB.AB
GDataDropped:Trojan.Banker.VB.AB
AhnLab-V3Trojan/Win32.Bancos.R148139
Acronissuspicious
McAfeePWS-Banker.gen.h
MAXmalware (ai score=100)
VBA32SIM.Trojan.VBO.0577
MalwarebytesMalware.AI.3676361923
PandaTrj/Banker.ANL
TrendMicro-HouseCallTSPY_BANCOS.BAD
RisingTrojan.Spy.Banbra.onq (CLOUD)
YandexTrojan.PWS.Bancos!awtBrPkp99w
IkarusTrojan-Spy.Win32.Bancos.ha
MaxSecureTrojan.bancos.ha
FortinetW32/Bancos.HA!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Malware.AI.3676361923?

Malware.AI.3676361923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment