Malware

Malware.AI.3955649773 (file analysis)

Malware Removal

The Malware.AI.3955649773 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3955649773 virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

www.bing.com
adf.ly
hurirk.net
cdn.hurirk.net
ajax.googleapis.com
d1a3jb5hjny5s4.cloudfront.net
ocsp.pki.goog
www.google-analytics.com
stats.g.doubleclick.net

How to determine Malware.AI.3955649773?


File Info:

crc32: 2FA74609
md5: b0d974380cdbb78e9188550cedb7b8a7
name: B0D974380CDBB78E9188550CEDB7B8A7.mlw
sha1: 51566ca3b0ff2efb45b3ef95baeccfae7513bc17
sha256: 13068d80b14e1503c4041a86228220bc1c36b9b6005a76c901bc7b3e25590b21
sha512: bec6ba503bb000fcd6db72feeb520fd5c8b6f4f48dcaf5befb0129d3704fb2b070d18f02ec14110c303def53cf08411d815b416c33473862ae0ca1a4f41ba698
ssdeep: 12288:kaWzgMg7v3qnCiMErQohh0F4CCJ8lny/QvP5XUt9Iwy:7aHMv6Corjqny/Qv1Pwy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 6, 1
FileVersion: 3, 3, 6, 1
FileDescription:
Translation: 0x0809 0x04b0

Malware.AI.3955649773 also known as:

K7AntiVirusTrojan ( 004b99901 )
LionicTrojan.Multi.Generic.4!c
MalwarebytesMalware.AI.3955649773
BitDefenderGen:Variant.Strictor.257287
K7GWTrojan ( 004b99901 )
Cybereasonmalicious.80cdbb
ESET-NOD32a variant of Win32/Injector.Autoit.DR
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Blocker.acko
AlibabaRansom:Win32/Blocker.be113504
NANO-AntivirusTrojan.Win32.Blocker.bgxbcv
TencentWin32.Trojan.Blocker.Pfjd
SophosMal/Generic-S
ComodoMalware@#ryj3mah7vq63
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen4.47675
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.StartPage.bh
EmsisoftGen:Variant.Strictor.257287 (B)
JiangminTrojan.Script.akxp
AviraTR/Dropper.Gen
ArcabitTrojan.Strictor.D3ED07
ZoneAlarmTrojan-Ransom.Win32.Blocker.acko
AhnLab-V3Malware/Win32.Generic.C1907231
MAXmalware (ai score=95)
IkarusTrojan-Ransom.Blocker
FortinetAutoIt/Injector.DR!tr
PandaTrj/CI.A
Qihoo-360Win32/Ransom.Blocker.HwoCj6MA

How to remove Malware.AI.3955649773?

Malware.AI.3955649773 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment