Malware

What is “Malware.AI.3785725452”?

Malware Removal

The Malware.AI.3785725452 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3785725452 virus can do?

  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
aasd.fah3jmab.com

How to determine Malware.AI.3785725452?


File Info:

crc32: 1B589125
md5: cfdcd4c356578b82343d11d9b4f816d4
name: CFDCD4C356578B82343D11D9B4F816D4.mlw
sha1: 2b1c2f8f66a218571651cd7b146e9c3db800e009
sha256: ddadef8bf8e07973bd33f9993398706843eef6eef17343a03c4b7dc2a681410c
sha512: a99061d8a4be96d1119aa1be51797d3415718edbb79481bfeeb8927f46f1441625c14ec81d6428f4e52d32d35346fcf325d1917d390ad9c40714e67df315fc95
ssdeep: 12288:wrFjXWnQ9q1TgtA2rUbpj0DAfX6fU3szIefHQnTkRGWa5S9:E9W0iMnr+10MEUUfQt8
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Copyright AdoberPlayer 2017
InternalName:
FileVersion: 34.10.0.2
CompanyName: PlayerWin
LegalTrademarks:
Comments:
ProductName: AdoberPlayer Updater
ProductVersion: 34.10.0.2
FileDescription: Adober Player Win Updater
OriginalFilename:
Editor: Adober
Translation: 0x0416 0x04e4

Malware.AI.3785725452 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Strictor.149086
FireEyeGeneric.mg.cfdcd4c356578b82
ALYacGen:Variant.Strictor.149086
MalwarebytesMalware.AI.3785725452
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Bcex.4!c
K7AntiVirusTrojan-Downloader ( 005079a11 )
BitDefenderGen:Variant.Strictor.149086
K7GWTrojan-Downloader ( 005079a11 )
Cybereasonmalicious.356578
CyrenW32/S-074d28b7!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Hesv.hoc
NANO-AntivirusTrojan.Win32.Bcex.emqpug
TencentWin32.Trojan.Bcex.Tdzo
Ad-AwareGen:Variant.Strictor.149086
EmsisoftGen:Variant.Strictor.149086 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S
AviraHEUR/AGEN.1119275
eGambitUnsafe.AI_Score_84%
Antiy-AVLTrojan/Win32.Bcex
ArcabitTrojan.Strictor.D2465E
ZoneAlarmTrojan.Win32.Hesv.hoc
GDataGen:Variant.Strictor.149086
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1855525
Acronissuspicious
McAfeeGeneric.axd
MAXmalware (ai score=80)
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.CAA
RisingMalware.Generic.5!tfe (C64:YzY0OuXbNE6wb7Bw)
YandexTrojan.GenAsa!SetDgn0OT9E
SentinelOneStatic AI – Suspicious PE
FortinetW32/Delf.CAA!tr
BitDefenderThetaAI:Packer.7124743D21
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Trojan.143

How to remove Malware.AI.3785725452?

Malware.AI.3785725452 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment