Malware

Malware.AI.3846021056 (file analysis)

Malware Removal

The Malware.AI.3846021056 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3846021056 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Created a service that was not started

How to determine Malware.AI.3846021056?


File Info:

crc32: C75F6F15
md5: d252d59cd00e209f22f9c5918e47c1de
name: D252D59CD00E209F22F9C5918E47C1DE.mlw
sha1: 157185c1fbcea294a529f1b8ed66377942d01b89
sha256: 788bd34d3c5d12b9767f8ac5587f1970597c47fb06713a6070d430a593bb4945
sha512: cd41403b1409b199303b0191cacc097566d7300e84de98c7718f4a9a1e448be06e8b2d7fc21aad279a5ac21c3e2d91ff2184f87ba1e7bb0e26d3e4fa47b8fe7c
ssdeep: 6144:AHsXNa2NLcCSSmyeq24dQ2XJhIOVhOcoK:Kia+QCSdyeq31XIDK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
InternalName: 7zS2.sfx
FileVersion: 9.20
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.20
FileDescription:
OriginalFilename: 7zS2.sfx.exe
Translation: 0x0409 0x04b0

Malware.AI.3846021056 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0054efe31 )
CynetMalicious (score: 99)
ALYacTrojan.DllHijacker
CylanceUnsafe
ZillyaTrojan.Dllhijacker.Win32.23
SangforTrojan.Win32.Tiggre.rfn
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Dllhijacker.22c7e232
K7GWTrojan ( 0054efe31 )
Cybereasonmalicious.cd00e2
CyrenW32/Trojan.UZJR-8311
ESET-NOD32a variant of Win32/LuckyMouse.BH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Dllhijacker.na
BitDefenderTrojan.GenericKD.34103699
NANO-AntivirusTrojan.Win32.Dllhijacker.isppnp
MicroWorld-eScanTrojan.GenericKD.34103699
TencentWin32.Trojan.Dllhijacker.Woza
Ad-AwareTrojan.GenericKD.34103699
ComodoMalware@#sbj3b30ye12z
BitDefenderThetaGen:NN.ZedlaF.34670.cu4@aOB@Jski
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DKU20
FireEyeTrojan.GenericKD.34103699
EmsisoftTrojan.GenericKD.34103699 (B)
SentinelOneStatic AI – Suspicious SFX
JiangminTrojan.DllHijacker.az
WebrootW32.Trojan.Gen
AviraTR/Agent.fhfrz
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Cryptinject.R!MTB
ArcabitTrojan.Generic.D2086193
AegisLabTrojan.Win32.Dllhijacker.4!c
GDataTrojan.GenericKD.34103699
McAfeeArtemis!D252D59CD00E
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.3846021056
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DKU20
RisingTrojan.Dllhijacker!8.ABDA (CLOUD)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AC.EB00
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Hijacker.HgIASOkA

How to remove Malware.AI.3846021056?

Malware.AI.3846021056 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment