Malware

What is “Malware.AI.3753894819”?

Malware Removal

The Malware.AI.3753894819 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3753894819 virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

2no.co
iplogger.org

How to determine Malware.AI.3753894819?


File Info:

crc32: 24891548
md5: 97bd6f5ae08b26ab544848365fe1f198
name: 97BD6F5AE08B26AB544848365FE1F198.mlw
sha1: f4f4200485436c40c4921b3887099cd0cc4413ae
sha256: 454a5ea8bd1eec5a972e694ee6c709d543da2a8c6220fdd00cbb697b0c3ff594
sha512: b5307e6d71f40f3e824e02f6c7d785055d8769868a72e94a95de889a9b642c8b9b4bbd8ae445ba1af7020ade232d59543e6d89edc1820399753151e4536dbcb0
ssdeep: 6144:es4jyRnAZlL7v4QpWjlojU2c5ENm2eK7mnoUSgpAY8ODcDcm7cIsgNLmDC3wQrD:IxjUxMNLmD7MFyR9OL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.3753894819 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053b7601 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Pico
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.187904
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Tosthin.021f8f0d
K7GWTrojan ( 0053b7601 )
Cybereasonmalicious.ae08b2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NSA
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan-Ransom.Win32.Encoder.kn
BitDefenderGeneric.Ransom.Thanatos.A8CB4481
NANO-AntivirusTrojan.Win32.Encoder.fhrebq
MicroWorld-eScanGeneric.Ransom.Thanatos.A8CB4481
Ad-AwareGeneric.Ransom.Thanatos.A8CB4481
SophosMal/Generic-R + Troj/Ransom-FAJ
BitDefenderThetaGen:NN.ZexaF.34738.ouW@aKddCIoi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.97bd6f5ae08b26ab
EmsisoftTrojan.FileCoder (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Encoder.an
AviraHEUR/AGEN.1109036
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27F5967
MicrosoftRansom:Win32/Tosthin.A
AegisLabTrojan.Win32.Encoder.4!c
GDataGeneric.Ransom.Thanatos.A8CB4481
AhnLab-V3Malware/Win32.Generic.C2730026
McAfeeArtemis!97BD6F5AE08B
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Gen
MalwarebytesMalware.AI.3753894819
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.92 (RDMK:Zj/i03Auyf/6hsf8ynSITQ)
YandexTrojan.GenAsa!2iwT0RajCa8
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.NSA!tr.ransom
AVGWin32:MalwareX-gen [Trj]

How to remove Malware.AI.3753894819?

Malware.AI.3753894819 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment