Malware

What is “Malware.AI.370984832”?

Malware Removal

The Malware.AI.370984832 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.370984832 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
pastebin.com
ocsp.digicert.com
1fichier.com

How to determine Malware.AI.370984832?


File Info:

crc32: 8B1A4C3E
md5: 11e0e6737b65621a2c40f6fe0d335cfb
name: 11E0E6737B65621A2C40F6FE0D335CFB.mlw
sha1: 5432740dc13bed64e189727cf65b571db4faa5bf
sha256: 7200a6991060c33fd9e4e3cda3745b6941c30600e7cbb3628883a0fc83820abb
sha512: 5b0e4b4a0ede9a6aff2b57204ca9d57969e610f0500a1ff9c22f81091ae59aac5a253ac6c6160ded2568cba5166003bfaa254751343a7b81c87be563f06a497a
ssdeep: 49152:a9N26FOnzGn6LJvqkwnpC+mWd6uIccNbPh:a906FOznLo0+Dd6uxcNbp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 9.1.0.0
ProductName: Setup
FileVersion: 9.1.0.0
OriginalFilename: suf_launch.exe
FileDescription: Setup Application
Translation: 0x0409 0x0000

Malware.AI.370984832 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45639322
FireEyeTrojan.GenericKD.45639322
McAfeeArtemis!11E0E6737B65
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45639322
K7GWRiskware ( 0040eff71 )
CyrenW32/Indiloadz.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Adload.scio
AlibabaTrojanDownloader:Win32/Adload.452f5e99
Ad-AwareTrojan.GenericKD.45639322
EmsisoftTrojan.GenericKD.45639322 (B)
ZillyaDownloader.Adload.Win32.100296
TrendMicroTROJ_GEN.R002C0WAV21
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
WebrootW32.Adware.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Ymacco.AB72
ArcabitTrojan.Generic.D2B8669A
ZoneAlarmTrojan-Downloader.Win32.Adload.scio
GDataTrojan.GenericKD.45639322
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4251457
ALYacTrojan.GenericKD.45639322
MalwarebytesMalware.AI.370984832
TrendMicro-HouseCallTROJ_GEN.R002C0WAV21
RisingDownloader.Adload!8.D1 (CLOUD)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Indiloadz.CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Adware.AdLoad.HgIASN8A

How to remove Malware.AI.370984832?

Malware.AI.370984832 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment