Malware

Malware.AI.3758861074 removal guide

Malware Removal

The Malware.AI.3758861074 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3758861074 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

z.whorecord.xyz
a.tomx.xyz
dssp.toolsabc.cn

How to determine Malware.AI.3758861074?


File Info:

crc32: 911D3936
md5: f828081dee54ee5b70426ea0dd36c2f8
name: F828081DEE54EE5B70426EA0DD36C2F8.mlw
sha1: 07c4dde17cb238a8b9b0ec13f1439a1ad73be4bf
sha256: acfbdd561930489694be16d84b86010c9834526337a44e7c7594e089c99f0db6
sha512: 7481adcb7cf12bb2ac8e9870cae5bfe02e548527ad9a0259869206f2e820a15375e4bcac9782fd02cd102a86bde4e5be27c11a528dde5ec646bc18d7099f64d4
ssdeep: 24576:nCPBUsjEFxEJowm6YqomiYtnv0XhrrUMdGXCGzSiXAL:nCPBE/EJowjYyi8nv0XhrUE0VSiXA
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2011
InternalName: WoWLauncher
FileVersion: 1, 0, 0, 1
ProductName: WoWLauncher
ProductVersion: 1, 0, 0, 1
FileDescription: WoWLauncher
OriginalFilename: WoWLauncher.exe
Translation: 0x0804 0x04b0

Malware.AI.3758861074 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.District.1
FireEyeGeneric.mg.f828081dee54ee5b
CAT-QuickHealTrojan.WacatacRI.S18008451
Qihoo-360Generic/Trojan.Ransom.d6f
ALYacGen:Variant.Ransom.District.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforRansom.Win32.District.1
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ransom.District.1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.dee54e
BitDefenderThetaGen:NN.ZexaF.34590.snLfaew1chmj
CyrenW32/Ransom.OXNL-2206
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
AlibabaTrojan:Win32/RansomX.583e2ffd
TencentMalware.Win32.Gencirc.11b39c6b
Ad-AwareGen:Variant.Ransom.District.1
EmsisoftGen:Variant.Ransom.District.1 (B)
F-SecureTrojan.TR/Ransom.District.sphdn
TrendMicroTROJ_GEN.R002C0RLH20
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S + Troj/AutoG-KS
SentinelOneStatic AI – Suspicious PE
AviraTR/Ransom.District.sphdn
Antiy-AVLTrojan/Win32.Generic
MicrosoftTrojan:Win32/Ymacco.AAAC
ArcabitTrojan.Ransom.District.1
GDataGen:Variant.Ransom.District.1
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4276274
McAfeeGenericRXAA-AA!F828081DEE54
MAXmalware (ai score=89)
VBA32BScope.Trojan.JakyllHyde
MalwarebytesMalware.AI.3758861074
ESET-NOD32a variant of Generik.EQTCSBJ
TrendMicro-HouseCallTROJ_GEN.R002C0RLH20
RisingMalware.Undefined!8.C (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/Generik.EQTCSBJ!tr
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.74051743.susgen

How to remove Malware.AI.3758861074?

Malware.AI.3758861074 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment