Categories: Malware

Malware.AI.3998642033 removal instruction

The Malware.AI.3998642033 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3998642033 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • The sample wrote data to the system hosts file.

Related domains:

z.whorecord.xyz
hack.map3q.com
a.tomx.xyz
download.map3q.com
www.bing.com

How to determine Malware.AI.3998642033?


File Info:

crc32: 2B62A9F9md5: 9e8f1b5e63ccddb8dea7eafd3400f30aname: 9E8F1B5E63CCDDB8DEA7EAFD3400F30A.mlwsha1: 1833fa83bf1ca11a74919500541db7046303d2besha256: 1dc72b5d304710003209ecfaf597f33d2c6615dad20ee1d3187b4520f8bb123dsha512: 957a94379f3ca4d01bee27f46a3104ea3bffbda3ec05991e3d744835a48b07f344fa30b7e597a30fbe150537ebb5ab64a8bde3a6df3864468f72482e691ddda0ssdeep: 12288:5quErHF6xC9D6DmR1J98w4oknqOOCyQfpipD+G2MXGv6eFTMk/gfKHENWg1jsML:Mrl6kD68JmlotQfGDlGv6WKKHE/wMLtype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 JacksonFileVersion: 1.0.0.0CompanyName: Copyright xa9 JacksonComments: Compile by AutoCompile - Jackson Vxf5ProductName: 1.0ProductVersion: 1.0.0.0FileDescription: Dx1b0x1a1ng Vxf5Translation: 0x0809 0x04b0

Malware.AI.3998642033 also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan ( 700000111 )
DrWeb Trojan.Hosts.45251
Cynet Malicious (score: 100)
Cylance Unsafe
CrowdStrike win/malicious_confidence_60% (W)
Alibaba Packed:Win32/Generic.042c545c
K7GW Trojan ( 700000111 )
Cybereason malicious.3bf1ca
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Win32/Packed.AutoIt.UP
APEX Malicious
Avast JS:ScriptSH-inf [Trj]
ClamAV Win.Malware.Generic-6837944-0
Kaspersky HEUR:Trojan.Win32.Generic
Tencent Malware.Win32.Gencirc.10b4d1b6
Sophos Generic ML PUA (PUA)
FireEye Generic.mg.9e8f1b5e63ccddb8
eGambit Unsafe.AI_Score_54%
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Malware/Win32.Generic.C3012062
Acronis suspicious
McAfee Artemis!9E8F1B5E63CC
VBA32 Trojan.Hosts
Malwarebytes Malware.AI.3998642033
TrendMicro-HouseCall TROJ_GEN.R002H07KE21
Ikarus Trojan.Win32.Autoit
Fortinet W32/PossibleThreat
AVG JS:ScriptSH-inf [Trj]
Paloalto generic.ml

How to remove Malware.AI.3998642033?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan.Win32.Agent.xbocpf removal

The Trojan.Win32.Agent.xbocpf is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

What is “Malware.AI.4092848701”?

The Malware.AI.4092848701 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

About “Trojan.Generic.35764356” infection

The Trojan.Generic.35764356 is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

What is “Generic.Dacic.94CCEEA9.A.D4FB9FDA”?

The Generic.Dacic.94CCEEA9.A.D4FB9FDA is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

What is “MSILHeracles.58916”?

The MSILHeracles.58916 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

About “TrojanDownloader:Win32/Beebone.AZ” infection

The TrojanDownloader:Win32/Beebone.AZ is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago