Malware

About “Malware.AI.3792251128” infection

Malware Removal

The Malware.AI.3792251128 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3792251128 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
pastebin.com

How to determine Malware.AI.3792251128?


File Info:

crc32: 3227C7D6
md5: b75dd6fcf8fc0ade19c03a1ac21feade
name: B75DD6FCF8FC0ADE19C03A1AC21FEADE.mlw
sha1: 4f9f038efca58cb9dc66e1ddabda06d118c9efb9
sha256: d914dc782ca867705fe14a0e5aeca545bc7ff35094fe042a9c0f0bc0f1408fb3
sha512: b0db93beb2a28c136c7ad195b72e00343d2dba5cf2b1e0bdf3f6cfd2ad218b2fd01dae9b58361644cbd23bffbc4b203ec7317dc9eccf212ff4a53f52376bbe65
ssdeep: 3072:aGovmTBy123mpqmBR/dMhQdGdbhk3Bu2oBZkn8i2UX:aGovmdytR/dlHI2o
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: ConsoleApplication2.exe
FileVersion: 1.0.0.0
ProductName: ConsoleApplication2
ProductVersion: 1.0.0.0
FileDescription: ConsoleApplication2
OriginalFilename: ConsoleApplication2.exe

Malware.AI.3792251128 also known as:

LionicTrojan.MSIL.Crypt.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.178441
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.CGL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.NMF
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Bulz.178441
NANO-AntivirusRiskware.Win32.Kryptik.ezfdql
TencentWin32.Trojan.Dropper.Pezl
Ad-AwareGen:Variant.Bulz.178441
SophosGeneric PUA EP (PUA)
ComodoMalware@#39sueksygfttk
BitDefenderThetaGen:NN.ZemsilF.34170.mm0@amr46zf
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.b75dd6fcf8fc0ade
EmsisoftGen:Variant.Bulz.178441 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.Bulz.D2B909
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Win-Trojan/MSILKrypt14.Exp
McAfeeGenericRXEH-FS!B75DD6FCF8FC
MAXmalware (ai score=95)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3792251128
PandaTrj/GdSda.A
RisingTrojan.Kryptik/MSIL!1.B224 (CLASSIC)
YandexTrojan.Kryptik!sw49zR108bQ
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.NFX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.3792251128?

Malware.AI.3792251128 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment