Malware

Malware.AI.3834066816 removal guide

Malware Removal

The Malware.AI.3834066816 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3834066816 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

Related domains:

make.campzephyr.host
create.guitarchange.site

How to determine Malware.AI.3834066816?


File Info:

name: 135E1FC005BEDF6CD5B2.mlw
path: /opt/CAPEv2/storage/binaries/22f64af4404ff37e53e00b94c4f33308360f5469286d93cea130ad4f9cb46dfc
crc32: B195BC0A
md5: 135e1fc005bedf6cd5b2feb623eb0497
sha1: 0c631399153f10da4e2167a05e3356aec0509391
sha256: 22f64af4404ff37e53e00b94c4f33308360f5469286d93cea130ad4f9cb46dfc
sha512: 4b8238a3ddba21441dc938bb146bf7e43b7813673f406a8a8b8004e72f98a32245ab49f43a234aac1774c6814196bf49cb8afd15d0faf76ea28b653a1858482c
ssdeep: 24576:EyULsv/AoywBrG022+N9lUsCZETLfY05IiyLTiXETH2C/XsvCqsZb3:/y6C02vN93TZOhnCP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1B533A1F4B71341E0EE3E3B88D4598D6939AFB12844EA4BAA024F1DDC70D36F126D57
sha3_384: ca92e8115ba5d6b952b7281cd47da3f482081125304328efe1a632e89aa8bb16fde9094213d912eaa0252a614d1111ab
ep_bytes: 558bec6aff68c0a15e006858175e0064
timestamp: 2015-03-24 07:28:22

Version Info:

FileVersion: 3.4.10.9
LegalCopyright: ©Roxolina
ProductName: NEOCTYTI
InternalName: NEOCTYTI.EXE
OriginalFilename: neoctyti.exe
ProductVersion: 3.4.10.9
CompanyName: ©Roxolina
Translation: 0x0409 0x04e4

Malware.AI.3834066816 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.StartSurf.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Bundler.BMJ
FireEyeGeneric.mg.135e1fc005bedf6c
ALYacApplication.Bundler.BMJ
ZillyaAdware.StartSurf.Win32.63382
K7AntiVirusTrojan ( 0053f6df1 )
AlibabaAdWare:Win32/StartSurf.c66622cf
K7GWTrojan ( 0053f6df1 )
Cybereasonmalicious.005bed
CyrenW32/Kryptik.DID.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMMA
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
BitDefenderApplication.Bundler.BMJ
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10cc61ec
Ad-AwareApplication.Bundler.BMJ
SophosMal/Generic-S + IStartSurfInstaller (PUA)
DrWebTrojan.Vittalia.17867
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.vz
EmsisoftApplication.Bundler.BMJ (B)
SentinelOneStatic AI – Malicious PE
GDataApplication.Bundler.BMJ
JiangminAdWare.StartSurf.oqj
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.28AFDB5
GridinsoftRansom.Win32.Zbot.sa
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FKC.R416163
McAfeePacked-FKC!135E1FC005BE
VBA32BScope.Adware.Prepscram
MalwarebytesMalware.AI.3834066816
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.StartSurf!Y2jXj5oH4Ic
IkarusPUA.Dlhelper
FortinetW32/Kryptik.GIQX!tr
BitDefenderThetaGen:NN.ZexaF.34294.sw0@a0GQUUji
AVGWin32:Adware-gen [Adw]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3834066816?

Malware.AI.3834066816 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment