Malware

How to remove “Malware.AI.3934563922”?

Malware Removal

The Malware.AI.3934563922 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3934563922 virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Starts servers listening on 0.0.0.0:21
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Code injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

supnewdmn.com
tvrstrynyvwstrtve.com
rtvwerjyuver.com
wqerveybrstyhcerveantbe.com

How to determine Malware.AI.3934563922?


File Info:

crc32: 69BE433C
md5: a3eaa018c44e2a2845f055ec4540f955
name: A3EAA018C44E2A2845F055EC4540F955.mlw
sha1: ae25345cff7409d88c37966fc8446435ff552a00
sha256: 64ffd832bc7a8654fb0373fe9ea24a11d6385ffbba1e616490b5420475beb6bd
sha512: 6114f00a8572d035756a74b4f901f5a0e8fa223b77cea0e7ad1de697f04ce437e5434e245d97bc7c675f04913ecbae02ecfbe9c04b3d7253b680418d0f58f4e0
ssdeep: 1536:ukO1U9fo2rTqfGRoJ410ibKvhog+bciy8nwsSAwR/SnglkmZX97uDAhsKEGB:uk59fo2r2f0oJDib8iLws7ngPwAGKEG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.3934563922 also known as:

K7AntiVirusTrojan ( 001869961 )
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Agent-1167536
CAT-QuickHealTrojan.Quolko.A
ALYacGen:Variant.Razy.352277
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Ramnit.6f634077
K7GWTrojan ( 001869961 )
Cybereasonmalicious.8c44e2
BitDefenderThetaGen:NN.ZexaF.34738.jqW@aiXtPnkc
CyrenW32/Bamital.I
SymantecW32.Ramnit.B
ESET-NOD32Win32/Ramnit.A
APEXMalicious
AvastWin32:MalOb-IJ [Cryp]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Ramnit.w
BitDefenderGen:Variant.Razy.352277
NANO-AntivirusTrojan.Win32.IRCNite.bsbnf
MicroWorld-eScanGen:Variant.Razy.352277
Ad-AwareGen:Variant.Razy.352277
ComodoBackdoor.Win32.Shiz.A@2nmfzb
DrWebTrojan.Siggen6.28287
TrendMicroTROJ_FAKEAV.SMUP
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
FireEyeGeneric.mg.a3eaa018c44e2a28
SophosML/PE-A + W32/Ramnit-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PornoBlocker.yg
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.858E
GDataGen:Variant.Razy.352277
AhnLab-V3Trojan/Win32.Ramnit.R249972
Acronissuspicious
VBA32Trojan.Ramnit
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3934563922
PandaTrj/Bamital.E
TrendMicro-HouseCallTROJ_FAKEAV.SMUP
TencentMalware.Win32.Gencirc.10b9a5af
YandexTrojan.Agent!2RekgkRwkvs
IkarusTrojan-Ransom.PornoBlocker
FortinetW32/Drooptroop.SMY!tr
AVGWin32:MalOb-IJ [Cryp]
Paloaltogeneric.ml

How to remove Malware.AI.3934563922?

Malware.AI.3934563922 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment