Malware

Malware.AI.3914991823 (file analysis)

Malware Removal

The Malware.AI.3914991823 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3914991823 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
widolapsed.info

How to determine Malware.AI.3914991823?


File Info:

crc32: D00E286A
md5: 46a85c3d50112b40aa89c6c685889160
name: 46A85C3D50112B40AA89C6C685889160.mlw
sha1: 71d6628830cdabd3f1f158543799628266887d20
sha256: 877c0c4537bce1b5e8730eaa12cb2ffbb0ad17067e7dcfd2b89c4985f33e4f17
sha512: cda83763333626b1147d5270ba96b4dd5c584f24e0bd2a5d784b936a42d17c4f473eeb392205525ad3d3bc4b3d24ba7320666e3cbf240b1ac46d6d13129057ee
ssdeep: 24576:c7LG7mvyJYwerANgJhhOgOwWo4b99Hx3VqE6+ITKgRIW5CnJiSQdM7Cn2pP2OYPN:c7TyderT/hOgeRrsIR3MOkpXgjRY
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Malware.AI.3914991823 also known as:

K7AntiVirusSpyware ( 005818c01 )
Elasticmalicious (high confidence)
DrWebBackDoor.TeamViewer.264
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Agent
ALYacDropped:Trojan.GenericKD.37485808
CylanceUnsafe
AlibabaBackdoor:Win32/Pavica.cc1e6119
K7GWSpyware ( 005818c01 )
CyrenW32/Trojan.YELI-1173
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Spy.Pavica.FS
AvastWin32:DangerousSig [Trj]
KasperskyBackdoor.NSIS.Agent.w
BitDefenderDropped:Trojan.GenericKD.37485808
NANO-AntivirusTrojan.Win32.TeamViewer.izzwyw
MicroWorld-eScanDropped:Trojan.GenericKD.37485808
Ad-AwareDropped:Trojan.GenericKD.37485808
SophosMal/Generic-S
Comodofls.noname@0
TrendMicroPUA.Win32.TeamBlunder.A
McAfee-GW-EditionGenericRXPY-CX!AC34AB95CBC2
FireEyeDropped:Trojan.GenericKD.37485808
EmsisoftDropped:Trojan.GenericKD.37485808 (B)
WebrootW32.Malware.Gen
AviraTR/Spy.Pavica.xehvt
MicrosoftTrojan:Win32/Tiggre!rfn
GDataDropped:Trojan.GenericKD.37485808
McAfeeArtemis!46A85C3D5011
MAXmalware (ai score=85)
VBA32Backdoor.TeamViewer
MalwarebytesMalware.AI.3914991823
PandaTrj/CI.A
IkarusTrojan-Spy.Agent
FortinetW32/Pavica.FS!tr.spy
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.3914991823?

Malware.AI.3914991823 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment