Malware

About “Malware.AI.3923028685” infection

Malware Removal

The Malware.AI.3923028685 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3923028685 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes
  • Uses suspicious command line tools or Windows utilities

Related domains:

nonnymainman.zapto.org

How to determine Malware.AI.3923028685?


File Info:

crc32: B7F6EDBE
md5: 7cb927ccf10acbc6bc87ae24d7b4fe00
name: 7CB927CCF10ACBC6BC87AE24D7B4FE00.mlw
sha1: 23d429a376869cef554eb644b7fa602aafcd7e46
sha256: ddf24e21ec5179154367ea8b0b5a2932c8ed321598e2539c6a2f4ac8957adfe2
sha512: 7397fbdeaa467970a1249ed30e8916f71a520bc1a3f9b00f5bdcc2d2f3249961fd1059cc30ff7000de169baf918ee88137d87afdc7210edd838ade60ed7d11c0
ssdeep: 12288:kjP2CKJmJCUsY6iuKcgN8qIcfPUE2xwRrCJOhy88yd:kjZ3JCdiCcHUtxwReghv8Q
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

FileDescription: Windows Script Host Runtime Library
Translation: 0x0409 0x04b0

Malware.AI.3923028685 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Comet.152
MicroWorld-eScanGen:Variant.Kazy.287500
FireEyeGeneric.mg.7cb927ccf10acbc6
McAfeeW32/Worm-FSD!Gamarue
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Variant.Kazy.287500
Cybereasonmalicious.cf10ac
BitDefenderThetaGen:NN.ZemsilF.34804.Hm0@amSMeUbi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.CCP
APEXMalicious
AvastWin32:Injector-BML [Trj]
KasperskyHEUR:Backdoor.Win32.Generic
NANO-AntivirusTrojan.Win32.DarkKomet.cnfjjl
RisingBackdoor.Generic!8.CE (TFE:dGZlOgww1PPbReEi8w)
Ad-AwareGen:Variant.Kazy.287500
EmsisoftGen:Variant.Kazy.287500 (B)
ComodoMalware@#1v8bm05uw7ryq
F-SecurePacked:MSIL/SmartIL.A
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Androm.bad
MaxSecureTrojan.Malware.300983.susgen
AviraBDS/Androm.becy
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Win32/Wacatac.DD!ml
ArcabitTrojan.Kazy.D4630C
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Variant.Kazy.287500
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Androm.C217908
MalwarebytesMalware.AI.3923028685
PandaGeneric Malware
IkarusBackdoor.Win32.DarkKomet
eGambitUnsafe.AI_Score_99%
FortinetW32/DarkKomet.BICK!tr.bdr
AVGWin32:Injector-BML [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM03.0.CA08.Malware.Gen

How to remove Malware.AI.3923028685?

Malware.AI.3923028685 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment