Malware

Malware.AI.3888227258 removal tips

Malware Removal

The Malware.AI.3888227258 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3888227258 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: jf_crazycf_1_4.exe
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
lightcf.ddns.net

How to determine Malware.AI.3888227258?


File Info:

crc32: 3ED5CA9A
md5: 8a060daac1e73524a227875e5da6eb3d
name: 8A060DAAC1E73524A227875E5DA6EB3D.mlw
sha1: 9cd8730422dc2553e028828feb370341da702061
sha256: 461f9398938a1c24fc0cfc2b350b8f2f707f228f3970181940a028663acb8da2
sha512: 9fee328d96c2c2df6bd9a37c835dd7272215f0952479d56f09d0371375bc758388c96a598319e6e11a3673e270738794177ef0ca9b8b817274b3d5d65eab0d87
ssdeep: 49152:5w80cTsjkWabAXZwFSqUTMRPHM/jozGVCWdzs1n3iclYFrxw9:W8sjkrOZuSqUTp7TVpZm3icler
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.3888227258 also known as:

K7AntiVirusTrojan ( 004915961 )
LionicTrojan.Win32.Generic.4!e
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.18286
ClamAVWin.Dropper.njRAT-7436651-0
CAT-QuickHealBackdoor.Bladabindi.AL3
MalwarebytesMalware.AI.3888227258
BitDefenderDropped:Generic.MSIL.Bladabindi.DA51F36F
K7GWTrojan ( 004915961 )
Cybereasonmalicious.ac1e73
BaiduMulti.Threats.InArchive
SymantecBackdoor.Ratenjay
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.MSIL.Disfa.bqg
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
MicroWorld-eScanDropped:Generic.MSIL.Bladabindi.DA51F36F
TencentMsil.Trojan.Disfa.Dzjq
Ad-AwareDropped:Generic.MSIL.Bladabindi.DA51F36F
SophosTroj/DotNet-P
BitDefenderThetaGen:NN.ZemsilF.34170.bmW@aq04lwo
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.wc
FireEyeGeneric.mg.8a060daac1e73524
EmsisoftDropped:Generic.MSIL.Bladabindi.DA51F36F (B)
WebrootW32.Trojan.MSIL.Disfa
AviraHEUR/AGEN.1142130
eGambitUnsafe.AI_Score_90%
Antiy-AVLTrojan/Generic.ASBOL.A8F4
GDataDropped:Generic.MSIL.Bladabindi.DA51F36F
AhnLab-V3Win-Trojan/Zbot.24064
MAXmalware (ai score=89)
TrendMicro-HouseCallBKDR_BLADABI.SMC
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
IkarusTrojan.MSIL.Bladabindi
FortinetW32/Auto.QE!tr
PandaTrj/CI.A

How to remove Malware.AI.3888227258?

Malware.AI.3888227258 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment