Malware

Malware.AI.68793286 (file analysis)

Malware Removal

The Malware.AI.68793286 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.68793286 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Bengali
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.68793286?


File Info:

crc32: 653D5884
md5: 00e3b69b18bfad7980c1621256ee10fa
name: 00E3B69B18BFAD7980C1621256EE10FA.mlw
sha1: b6cf6789c3b19ca82d12655274df7f9c302da794
sha256: c8462829871b7bdb005f4dd881d253aa255a1b2f6f3d89edb1d609b51f5d04fd
sha512: 30cab0ba2a1e7a8d8c2da100c1eb7e06cb36012a7f67cceee1c3388d718c29d7a3f5543a3c41e7d07aaadde14bee873f4c9b29301460d7f473e2549830576ff9
ssdeep: 24576:8B8LCHrjTWTHTkRDene4Xgez7d7A8AA6os3xyloB183SlrwCLk:y8OHz8zkRDeeigcfBDo0ocCLk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 1984-2012 Adobe Systems Incorporated and its licensors. All rights reserved.
Assembly Version: 0.0.0.0
InternalName: temp.exe
FileVersion: 11.0.10.32
CompanyName: Adobe Systems Incorporated
Comments: Adobe Reader
ProductName: Adobe Reader
ProductVersion: 11.0.10.32
FileDescription: AcroRd32
OriginalFilename: temp.exe

Malware.AI.68793286 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.263
CynetMalicious (score: 99)
ALYacTrojan.Ransom.Kriptovor
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.15518
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Purubutu.fe4e8fc3
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.b18bfa
SymantecRansom.Kriptovor
ESET-NOD32Win32/Filecoder.NDK
APEXMalicious
AvastWin32:Ransom-AVW [Trj]
KasperskyBackdoor.Win32.Androm.gbyq
BitDefenderGen:Variant.Fugrafa.96616
NANO-AntivirusTrojan.Win32.Agent.dnkbur
MicroWorld-eScanGen:Variant.Fugrafa.96616
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Fugrafa.96616
SophosMal/Generic-S
ComodoMalware@#39wlowy6f51ji
BitDefenderThetaGen:NN.ZexaF.34686.Hv3@amsZM!hG
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_KRYPTOVOR.A
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Fugrafa.96616
EmsisoftGen:Variant.Fugrafa.96616 (B)
JiangminTrojan/Generic.bcjie
WebrootW32.Malware.Gen
AviraTR/Dropper.A.37700
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Hack.Androm.gb.(kcloud)
MicrosoftRansom:Win32/Purubutu
AegisLabTrojan.Win32.Androm.4!c
GDataGen:Variant.Fugrafa.96616
AhnLab-V3Trojan/Win32.Gen
McAfeeArtemis!00E3B69B18BF
MAXmalware (ai score=100)
VBA32TrojanPSW.Tepfer
MalwarebytesMalware.AI.68793286
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_KRYPTOVOR.A
YandexTrojan.Injector!H6400QBG12w
IkarusTrojan.Win32.Injector
FortinetW32/Injector.AJAR!tr
AVGWin32:Ransom-AVW [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.68793286?

Malware.AI.68793286 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment