Malware

Malware.AI.3859089018 removal guide

Malware Removal

The Malware.AI.3859089018 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3859089018 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Attempts to delete volume shadow copies
  • Exhibits possible ransomware file modification behavior
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Appends a known Sage ransomware file extension to files that have been encrypted
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
mbfce24rgn65bx3g.rzunt3u2.com
mbfce24rgn65bx3g.er29sl.com

How to determine Malware.AI.3859089018?


File Info:

crc32: 9FACC614
md5: 7928f5be2e624937ee11d1f43672d768
name: 7928F5BE2E624937EE11D1F43672D768.mlw
sha1: 1b3c0a83a1b0c686e06790691201865b70033d05
sha256: a2b7882a3312d376258d0422a3bb331f4bb400c23c7b26223684695a1e621ed3
sha512: a15d8178664d8d6a17c586e07bff7d7ae15242714fc0c12b4e01f3b1d3f326f2da72f6bf084ec43d6f9c1cdf535c68c8ffd7a4d9baf90786a61d52843f99baf5
ssdeep: 6144:jTzqhaAQYWkoo8CI2p9lw450hIEw+awWC:jTOhR6ko9H2p9l0aEw+a9C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 avby o qaut
InternalName: Hicliz
FileVersion: 6.556
CompanyName: Tesw qlrl
ProductName: Rgj hy qreguhmf bptrzc
ProductVersion: 6.556
FileDescription: Amiwxfm zqhiamn qv uy mzkuttm
OriginalFilename: Hicliz
Translation: 0x0027 0x000a

Malware.AI.3859089018 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.14805
MicroWorld-eScanGen:Variant.Ransom.Sage.30
FireEyeGeneric.mg.7928f5be2e624937
CAT-QuickHealTrojanransom.Sagecrypt
Qihoo-360Win32/Trojan.Generic.HwcBMT0A
McAfeeRansom-FCJ!7928F5BE2E62
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforVirus_Suspicious.Win32.Sality.ae
K7AntiVirusTrojan ( 005036521 )
BitDefenderGen:Variant.Ransom.Sage.30
K7GWTrojan ( 005036521 )
Cybereasonmalicious.e2e624
BitDefenderThetaGen:NN.ZexaF.34590.rq1@a0vf2hni
CyrenW32/Ransom.CN.gen!Eldorado
SymantecRansom.Cry!g1
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Sage-5670507-0
KasperskyTrojan.Win32.Deshacop.dst
AlibabaTrojan:Win32/Deshacop.ff69dc12
NANO-AntivirusTrojan.Win32.Deshacop.eleexs
RisingRansom.Milicry!8.A2F2 (C64:YzY0Or/SVJGSxsX0)
Ad-AwareGen:Variant.Ransom.Sage.30
EmsisoftGen:Variant.Ransom.Sage.30 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
ZillyaTrojan.Deshacop.Win32.766
TrendMicroRansom_HPMILICRY.SM1
McAfee-GW-EditionRansom-FCJ!7928F5BE2E62
SophosML/PE-A + Troj/Ransom-EDF
IkarusTrojan.Atros4
JiangminTrojan.Deshacop.uk
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen7
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Milicry.A
ArcabitTrojan.Ransom.Sage.30
ZoneAlarmTrojan.Win32.Deshacop.dst
GDataGen:Variant.Ransom.Sage.30
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Deshacop.C1761879
Acronissuspicious
ALYacGen:Variant.Ransom.Sage.30
VBA32SScope.TrojanRansom.WannaCry
MalwarebytesMalware.AI.3859089018
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FSFF
TrendMicro-HouseCallRansom_HPMILICRY.SM1
TencentMalware.Win32.Gencirc.10bb878f
YandexTrojan.Deshacop!8BDgMRIDAkM
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FNGP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3859089018?

Malware.AI.3859089018 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment