Malware

Malware.AI.3986193187 malicious file

Malware Removal

The Malware.AI.3986193187 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3986193187 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Malware.AI.3986193187?


File Info:

crc32: 8C61518C
md5: 25eade47d5526a9a9c39590a343cadbb
name: 25EADE47D5526A9A9C39590A343CADBB.mlw
sha1: d2045f198d160de5dd9293b3d63879feef15e92a
sha256: e9da6a0b4286254c17428999fb62c27986b4c698d4dadda990eac485c296b25b
sha512: 6ba96ffcef6904507b064c8d4c2f68f10877cf54daca993286dca0ae95fbd3e5248ff588e01cb47871143d4fbca148e3335fefd6934e4c027e6af3344f0b5dcb
ssdeep: 3072:bdY+VXUl6U1kKcSqYNPXUizEc0Zopv2YGrqRwqH:b6+VQuDEPwwvKAw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2011 Igor Pavlov
InternalName: 7zg
FileVersion: 9.23 alpha
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 9.23 alpha
FileDescription: 7-Zip GUI
OriginalFilename: 7zg.exe
Translation: 0x0409 0x04b0

Malware.AI.3986193187 also known as:

K7AntiVirusNetWorm ( 0040f8bd1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Kuluoz.4
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Zusy.322691
ZillyaDownloader.Zortob.Win32.59
CrowdStrikewin/malicious_confidence_100% (D)
K7GWNetWorm ( 0040f8bd1 )
Cybereasonmalicious.7d5526
BaiduWin32.Trojan.Kryptik.hj
CyrenW32/Trojan.YDVM-2065
SymantecTrojan.Asprox.B
ESET-NOD32Win32/TrojanDownloader.Zortob.B
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Kuluoz-7005718-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.322691
NANO-AntivirusTrojan.Win32.Kuluoz.dbvcau
MicroWorld-eScanGen:Variant.Zusy.322691
TencentMalware.Win32.Gencirc.10b2f716
Ad-AwareGen:Variant.Zusy.322691
SophosML/PE-A + Troj/Agent-AHOE
ComodoTrojWare.Win32.Agent.BDQY@5bl9e0
BitDefenderThetaAI:Packer.D1C7C32F20
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_KULUOZ.SM02
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.25eade47d5526a9a
EmsisoftGen:Variant.Zusy.322691 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fgdrm
AviraHEUR/AGEN.1101354
MicrosoftRansom:Win32/CerberCrypt.PB!MTB
ArcabitTrojan.Zusy.D4EC83
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Variant.Zusy.322691
TACHYONWorm/W32.Aspxor.192512
AhnLab-V3Win-Trojan/Kuluoz.192512.B
McAfeePacked-AM!25EADE47D552
MAXmalware (ai score=81)
VBA32BScope.Trojan.Jorik
MalwarebytesMalware.AI.3986193187
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KULUOZ.SM02
IkarusTrojan-Downloader.Win32.Zortob
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dridex.DD!tr
AVGWin32:Trojan-gen

How to remove Malware.AI.3986193187?

Malware.AI.3986193187 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment