Malware

Malware.AI.1063654746 removal

Malware Removal

The Malware.AI.1063654746 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1063654746 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1063654746?


File Info:

name: 3C7DD41B5C99E7E63DCD.mlw
path: /opt/CAPEv2/storage/binaries/fa41f3bd4899f74adc17a93c60247cf1395a5d7186242a22847ba123a4912ec1
crc32: 19EA0C04
md5: 3c7dd41b5c99e7e63dcd6a90b65a9367
sha1: afd5b9576ee71ebd8382bca0cc678a243c341cc8
sha256: fa41f3bd4899f74adc17a93c60247cf1395a5d7186242a22847ba123a4912ec1
sha512: 172e5b794e687dd58156f876aafee8247f00805691e598b5ba7fab672fad1ade3512e2188095f7cdc23c3431bd16c12047cee8dca306f31af524109882446062
ssdeep: 24576:wyay4oHJrBfJXAENI3l5AvIRK2RTwhr0acXhgimO8WD+e23HHU99UTedMpSZXdp:TlBfJXAEG3B0CUrHcXSisWDSnU9eOvX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A675F180BED5CCADE5A50478CB70964CD86DFC63BFAD46CE2360891AD9F5083253E1AD
sha3_384: 8a27888a7ed909ae39d3d60d844a3c7b2b773dbf78385433c35b430554615668eedda8c873407d03c07467b10ebb0437
ep_bytes: e8e4040000e988feffff3b0d18d54300
timestamp: 2020-06-25 10:38:36

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 5.91.0
ProductVersion: 5.91.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2020
OriginalFilename: WinRAR.exe
Translation: 0x0409 0x04e4

Malware.AI.1063654746 also known as:

MicroWorld-eScanTrojan.Uztuby.4
FireEyeTrojan.Uztuby.4
CAT-QuickHealW32.BrowserAssistant.B7
K7AntiVirusTrojan ( 0057be3e1 )
BitDefenderTrojan.Uztuby.4
K7GWTrojan ( 0057be3e1 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Trojan.VPVY-1105
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ERTY
KasperskyTrojan.Win32.Agent.xapokg
RisingTrojan.Generic@AI.100 (RDML:mjSUmPqTu33iHoKEkstlHQ)
Ad-AwareTrojan.Uztuby.4
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.Uztuby.4 (B)
AviraHEUR/AGEN.1242204
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
GDataTrojan.Uztuby.4
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R456326
McAfeeArtemis!3C7DD41B5C99
MAXmalware (ai score=63)
MalwarebytesMalware.AI.1063654746
IkarusTrojan.Win32.Injector
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Malware.AI.1063654746?

Malware.AI.1063654746 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment