Malware

How to remove “Malware.AI.880325806”?

Malware Removal

The Malware.AI.880325806 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.880325806 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

gta.nds89.com

How to determine Malware.AI.880325806?


File Info:

name: 3914297C25829FF765C9.mlw
path: /opt/CAPEv2/storage/binaries/af7f2cb63d3383bcb4e7904ae30ce55ce38efc0cc5bcb0ae0aa1ba632f26b2c6
crc32: 7229F2AD
md5: 3914297c25829ff765c9c497d5582f3d
sha1: 93b9526306cc871ac48dc9a3d37219321b3e6d77
sha256: af7f2cb63d3383bcb4e7904ae30ce55ce38efc0cc5bcb0ae0aa1ba632f26b2c6
sha512: 8412a8814f799fc6d25368ffe33374f1ae9eb56930924430cc1b6f7a5663d04ca628a031b6c7f637586baea58e27f50c2031899656325c06f2cde1633474e69b
ssdeep: 24576:t8vJlxs9PYsf+Ish64N4Ndt3SlsUPc/h+m6Swgn7yRomvLkBbQSOUUH5wovOejhk:tpYzBLhk/h+mN7ytvNSOHL/hr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186B58CDEA392CC32E4E7D674CB1746946935EE122A24598627A43CCC3FB7281371F293
sha3_384: ab79c4301d8044ad3ab7b208d0047d8a49b3ed0462cf81a78fde3d0a432ae1c7442868fdd71ed2cbb43a6ab4e8aafccf
ep_bytes: 558bec83c4f0535657b864065200e8c1
timestamp: 2021-09-01 05:18:46

Version Info:

CompanyName: Book Same
FileDescription: Book Smart
FileVersion: 35.21.33.2
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 35.21.33.2
Comments:
Translation: 0x0409 0x04e4

Malware.AI.880325806 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.393236
FireEyeGen:Variant.Zusy.393236
McAfeeTrojan-FTWY!3914297C2582
CrowdStrikewin/malicious_confidence_60% (D)
ESET-NOD32a variant of Win32/Injector.EPMC
KasperskyHEUR:Backdoor.Win32.Crypminal.gen
BitDefenderGen:Variant.Zusy.393236
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.11cca1da
Ad-AwareGen:Variant.Zusy.393236
EmsisoftGen:Variant.Zusy.393236 (B)
ZillyaBackdoor.Crypminal.Win32.28
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosML/PE-A
GDataGen:Variant.Zusy.393236
JiangminBackdoor.Crypminal.aq
Antiy-AVLTrojan/Generic.ASMalwS.348B4C9
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4626458
ALYacGen:Variant.Zusy.393236
MAXmalware (ai score=86)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.880325806
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.EPMC!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.880325806?

Malware.AI.880325806 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment