Malware

Malware.AI.3867227997 removal instruction

Malware Removal

The Malware.AI.3867227997 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3867227997 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Malware.AI.3867227997?


File Info:

crc32: 167D4AC3
md5: 9cfd78fcc5a9dfb9361da349904c42ee
name: 9CFD78FCC5A9DFB9361DA349904C42EE.mlw
sha1: 9b469afb189d1d6b914295677bcc1188e88b8adc
sha256: 586d5a14671711742ae114630e158f89fe6c2f5955c0a6881a1cb39df4cd78d0
sha512: d9719c1f05022b1eb0f765d21b12dcc7c330376b5f76162c892b79671c063868ca83cfc07f0951deaaba0b6a1dc8857076c68eeacd95b67fc348f04811d8923c
ssdeep: 12288:Ch9B+tWrRUCRvVX1xGb9gKkdw2+UDd4H+TcN3pnesJdT2OmC7:Ch9BzVUCRvBXAKBdyUDCHQ03ZesJdT2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2018 Google LLC
InternalName: Google Update
FileVersion: 1.3.36.71
CompanyName: Google LLC
ProductName: Google Update
ProductVersion: 1.3.36.71
FileDescription: Google Installer
OriginalFilename: GoogleUpdate.exe
Translation: 0x0400 0x04b0

Malware.AI.3867227997 also known as:

K7AntiVirusVirus ( 00580a951 )
Elasticmalicious (high confidence)
DrWebWin32.Expiro.150
ALYacWin32.Expiro.Gen.6
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWVirus ( 00580a951 )
Cybereasonmalicious.cc5a9d
CyrenW32/Expiro.S.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDG
APEXMalicious
AvastWin32:MalOb-FE [Cryp]
CynetMalicious (score: 100)
KasperskyHEUR:Virus.Win32.Expiro.gen
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanWin32.Expiro.Gen.6
Ad-AwareWin32.Expiro.Gen.6
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34170.Hu0@amc2ZmpP
TrendMicroVirus.Win32.EXPIRO.AD
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.9cfd78fcc5a9dfb9
EmsisoftWin32.Expiro.Gen.6 (B)
SentinelOneStatic AI – Malicious PE
AviraW32/Infector.Gen8
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitWin32.Expiro.Gen.6
GDataWin32.Expiro.Gen.6
AhnLab-V3Virus/Win.Expiro.X2115
Acronissuspicious
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.3867227997
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG!tr
AVGWin32:MalOb-FE [Cryp]

How to remove Malware.AI.3867227997?

Malware.AI.3867227997 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment