Malware

Malware.AI.4249678636 information

Malware Removal

The Malware.AI.4249678636 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4249678636 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.

Related domains:

z.whorecord.xyz
a.tomx.xyz
evolution2008.no-ip.org
lostbox.mine.nu

How to determine Malware.AI.4249678636?


File Info:

crc32: C8C97EFE
md5: 3387fc73697927f593b63f7da61ae4ed
name: 3387FC73697927F593B63F7DA61AE4ED.mlw
sha1: 40479ec24b6e64cb780b1aeec7e03a9cacbe2799
sha256: 215c3031a60107ba7377372874714ea0947d86d1580b8366a4de2eef21af2f1d
sha512: c4b2339001b7424ba0b8b33d61c18908086c9b922f68784e313838c9e14d972fbe67cbac012c5444089cf9bf87a9df3802e6927242f0996e812a4a800a84d874
ssdeep: 12288:8pqiC/2OGAtkCP4cejGSOpRKYCNLJCtmCL1XSGW+SZQQFTRjqNBF2rnRt:8po/2+ttPJLfpRKYCxJCU9GW+TaReKRt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.4249678636 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.3230646
CylanceUnsafe
ZillyaTrojan.Spatet.Win32.7540
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaPacked:Win32/Spatet.b24bc483
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.369792
CyrenW32/A-254ad5f8!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
KasperskyPacked.Win32.Krap.im
BitDefenderTrojan.GenericKD.3230646
NANO-AntivirusTrojan.Win32.Krap.feemay
MicroWorld-eScanTrojan.GenericKD.3230646
TencentWin32.Packed.Krap.Ljal
Ad-AwareTrojan.GenericKD.3230646
SophosMal/Generic-R + Troj/AutoIt-NM
ComodoMalware@#25fmljplrzgst
BitDefenderThetaAI:Packer.CC4C9C4716
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.3387fc73697927f5
EmsisoftTrojan.GenericKD.3230646 (B)
AviraTR/Dropper.Gen
eGambitGeneric.Dropper
KingsoftWin32.Troj.Krap.im.(kcloud)
MicrosoftTrojan:Win32/Occamy.C21
GDataTrojan.GenericKD.3230646
McAfeeArtemis!3387FC736979
MAXmalware (ai score=99)
VBA32Trojan.Autoit.Injcrypt
MalwarebytesMalware.AI.4249678636
PandaTrj/CI.A
YandexWorm.Rebhip!jqVk7ZBRDRE
IkarusTrojan.Win32.Spatet
MaxSecureWorm.Win32.AutoIt.QN
FortinetW32/Fynloski.AM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4249678636?

Malware.AI.4249678636 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment