Malware

Malware.AI.3969984048 removal guide

Malware Removal

The Malware.AI.3969984048 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3969984048 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3969984048?


File Info:

crc32: 35147CB5
md5: 2aac565663050a9c96e13e6825168ce8
name: 2AAC565663050A9C96E13E6825168CE8.mlw
sha1: 0ff0e1b06d7a5571cc2c0057475e6ecb08ac75c4
sha256: 24a94c04a07c6b97ab6b227ab73f91b449e8798ad59a71c92bb311104f057aa6
sha512: 44c883ea18f77d360471b70f721d90ce41e64a5b97fd81eb9f64f4207ab21496e4a7497cc0371942d6ea3922eabc19f450e992683a859ff2e011de570a64350e
ssdeep: 3072:r3o/7Mq1kqsi5XzBQJOcqucta7++7+6ew33sfPTVP:r3+7M+kqsQKJpq7ta7++7+6x38X9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 2014
InternalName: cluster
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: cluster
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: cluster
OriginalFilename: cluster.exe
Translation: 0x0810 0x04b0

Malware.AI.3969984048 also known as:

K7AntiVirusTrojan ( 0040f8461 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.5676
CynetMalicious (score: 99)
ALYacTrojan.Lethic.Gen.4
CylanceUnsafe
ZillyaTrojan.Injector.Win32.236440
K7GWTrojan ( 0040f8461 )
Cybereasonmalicious.663050
CyrenW32/Zbot.RS.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Injector.BDES
APEXMalicious
AvastWin32:Crypt-REG [Trj]
ClamAVWin.Trojan.Zbot-57618
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Lethic.Gen.4
NANO-AntivirusTrojan.Win32.Inject.cxiprh
MicroWorld-eScanTrojan.Lethic.Gen.4
TencentMalware.Win32.Gencirc.10b4539e
Ad-AwareTrojan.Lethic.Gen.4
SophosMal/Generic-R + Troj/Fondu-AS
ComodoTrojWare.Win32.Injector.BDES@59xvmr
BitDefenderThetaGen:NN.ZexaF.34266.zq0@a8T08Fpb
VIPRETrojan.Win32.Agent.bciw (v)
TrendMicroTROJ_MALKRYP.SM5
McAfee-GW-EditionPWSZbot-FXE!2AAC56566305
FireEyeGeneric.mg.2aac565663050a9c
EmsisoftTrojan.Lethic.Gen.4 (B)
JiangminTrojanSpy.Zbot.edwu
AviraTR/Mantsu.vxca
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.9D2FC3
MicrosoftBackdoor:MSIL/Bladabindi.AN
SUPERAntiSpywareTrojan.Agent/Gen-Banload
GDataTrojan.Lethic.Gen.4
AhnLab-V3Trojan/Win32.Injector.R106674
McAfeePWSZbot-FXE!2AAC56566305
MAXmalware (ai score=81)
VBA32OScope.Malware-Cryptor.Zbot
MalwarebytesMalware.AI.3969984048
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_MALKRYP.SM5
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazo8TWt33pw/wffsXzQE+GH2)
YandexTrojan.GenAsa!SXWwvm30QiI
IkarusVirus.Win32.Zbot
FortinetW32/Krypt.DE!tr
AVGWin32:Crypt-REG [Trj]

How to remove Malware.AI.3969984048?

Malware.AI.3969984048 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment