Malware

Malware.AI.3794460504 removal

Malware Removal

The Malware.AI.3794460504 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3794460504 virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Azeri (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3794460504?


File Info:

crc32: 216D5AED
md5: bbb23762f373533f891e81c75fbf3cb5
name: BBB23762F373533F891E81C75FBF3CB5.mlw
sha1: bb1733be5af137fc5bc8456d23052c2daeb2dbd0
sha256: 2be898ec58e791f1b7849b673c95f5698aafd023a078fec06dadd7f62bd27693
sha512: 21b835a546ebd82be7f80b71a14217901fbd9fe0950957b801928457479c31ce1b46077ac923f2d702135f9d2a1d9749782a456e4e50145db49b30a12d3566f1
ssdeep: 3072:ckfO5KvQ1Jxq4ga3zM/4CjnDpRuKiBJiudj5CkBNN:cIOoyb3zM/fje/7DdzBX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: ks6j
InternalName: kkstryk
FileVersion: 71.0.0.1
CompanyName: jftyuk
ProductName: sdrtlkstyk
ProductVersion: 51.0.0.1
FileDescription: sdtrjy
OriginalFilename: kdstul
Translation: 0x0048 0x04b0

Malware.AI.3794460504 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.86460
FireEyeGeneric.mg.bbb23762f373533f
CAT-QuickHealTrojandownloader.Tovkater
Qihoo-360HEUR/QVM11.1.0B1B.Malware.Gen
McAfeeGenericRXCZ-LZ!57A0921C788A
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 005194e41 )
BitDefenderGen:Variant.Symmi.86460
K7GWTrojan-Downloader ( 005194e41 )
Cybereasonmalicious.2f3735
CyrenW32/Taterf.A!Generic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Tovkater.etvdqd
RisingMalware.Obscure/Heur!1.A89E (RDMK:cmRtazrVkIRAJl9ROsOL0g+jFf9V)
Ad-AwareGen:Variant.Symmi.86460
EmsisoftGen:Variant.Symmi.86460 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.InstallMonster.2401
ZillyaDownloader.Tovkater.Win32.995
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
IkarusTrojan.Krypt
AviraTR/Crypt.XPACK.Gen7
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Symmi.D151BC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.86460
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Abnores.R211818
BitDefenderThetaGen:NN.ZexaF.34804.kmLfaa9!wocG
ALYacGen:Variant.Symmi.86460
MAXmalware (ai score=85)
VBA32TrojanDownloader.Tovkater
MalwarebytesMalware.AI.3794460504
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.FF
YandexTrojan.DL.Tovkater!wc5YBNxHEUs
SentinelOneStatic AI – Malicious PE
FortinetW32/Tovkater.FQ!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3794460504?

Malware.AI.3794460504 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment