Malware

Malware.AI.3042484570 (file analysis)

Malware Removal

The Malware.AI.3042484570 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3042484570 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Likely virus infection of existing system binary

How to determine Malware.AI.3042484570?


File Info:

name: 7B613FF47063BCB6777B.mlw
path: /opt/CAPEv2/storage/binaries/5061ef70c66c35da1d49ae6210e5fead197c2c3eeb8ef76096e621ff5b2297d2
crc32: 9591AE76
md5: 7b613ff47063bcb6777b8b371c103a95
sha1: c244cb70dd7177684f5655f38abbbdd3392653e9
sha256: 5061ef70c66c35da1d49ae6210e5fead197c2c3eeb8ef76096e621ff5b2297d2
sha512: b34c9716e2e376b57e0c30eeba80843ffe7c2a5282561cff937c7326131e90498047d6f49512b239ca5299b61db8d4123fee98836865f4150b0b26706585253f
ssdeep: 3072:+PgpdXXRvjxCb5NgXDY7uSlkJcUa7kYQTcqW2NdQQGH/UDhSCUc4aqTBWYlrp:iglKgzelZNQSBQGH/CSpWqT3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5B4F15179E2C8B2C486853A5CAA8B269737B9178A74D143B7D90E8F6F713C49F2F301
sha3_384: ce0d5215af5ec8e32d0625257a068c124a122531cb0433192a0a4b9a40fe08d5e3bc174b5ae617147f41da29af72d369
ep_bytes: e812470000e916feffff558bec81ec28
timestamp: 2008-09-27 04:51:42

Version Info:

CompanyName: Oracle Corporation
FileDescription: VirtualBox Guest Additions Utility
FileVersion: 4.1.2.73507
InternalName: VBoxControl
LegalCopyright: Copyright (C) 2009-2011 Oracle Corporation
OriginalFilename: VBoxControl.exe
ProductName: Oracle VM VirtualBox Guest Additions
ProductVersion: 4.1.2.r73507
Translation: 0x0409 0x04b0

Malware.AI.3042484570 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cosmu.tror
Elasticmalicious (high confidence)
MicroWorld-eScanWorm.Generic.388260
CAT-QuickHealW32.Cosmu.D4
McAfeeGenericRXFU-SQ!7B613FF47063
CylanceUnsafe
ZillyaWorm.Cosmu.Win32.36
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaMalware:Win32/km_2481f39.None
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.47063b
BaiduWin32.Worm.Agent.bg
CyrenW32/Agent.BYQ.gen!Eldorado
SymantecW32.Coinbitminer
ESET-NOD32Win32/Agent.NLP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Cosmu.dnej
BitDefenderWorm.Generic.388260
NANO-AntivirusTrojan.Win32.Agetn2.bbdyxx
AvastWin32:Malware-gen
TencentTrojan.Win32.Cosmu.c
Ad-AwareWorm.Generic.388260
SophosML/PE-A + W32/Renamer-I
ComodoTrojWare.Win32.Cosmu.NLP@7v4zem
DrWebWin32.HLLW.Siggen.10550
VIPREWorm.Win32.Renamer.i (v)
TrendMicroTROJ_GEN.R002C0CLA21
McAfee-GW-EditionBehavesLike.Win32.Generic.hz
FireEyeGeneric.mg.7b613ff47063bcb6
EmsisoftWorm.Generic.388260 (B)
IkarusWorm.Agent
GDataWorm.Generic.388260
JiangminWorm/Generic.abjq
AviraWORM/Agent.2170901
Antiy-AVLTrojan/Generic.ASMalwS.12C063
ArcabitWorm.Generic.D5ECA4
MicrosoftVirus:Win32/Emdup.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cosmu.R230705
Acronissuspicious
VBA32Trojan.Cosmu
ALYacWorm.Generic.388260
MAXmalware (ai score=81)
MalwarebytesMalware.AI.3042484570
TrendMicro-HouseCallTROJ_GEN.R002C0CLA21
RisingWorm.Agent!1.DAFA (CLASSIC)
YandexTrojan.Cosmu!2qxg61+LWtE
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Naglov.OA!tr
BitDefenderThetaGen:NN.ZexaF.34084.Fq3@aO1CTil
AVGWin32:Malware-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.121218.susgen

How to remove Malware.AI.3042484570?

Malware.AI.3042484570 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment