Malware

What is “Malware.AI.3096603105”?

Malware Removal

The Malware.AI.3096603105 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3096603105 virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.3096603105?


File Info:

crc32: C8F1B149
md5: c638e8327f9bbf1b0acadfc1a7a3cdd0
name: C638E8327F9BBF1B0ACADFC1A7A3CDD0.mlw
sha1: 57e822f7ea9c96d9e6997cb7fe85b7f279c6e810
sha256: 9bf20509ce5be3d8dd7afed314d9739a5a4e241bab4a6e3b8946f8b3a88c3ce9
sha512: 3f9549e95582cd3ab77694f292abf38d26f2dddce322cd1325c480e436a467fe939aa2478d4eeb655ffce3be7a961b1471fbeac53bc492b9d02253142ac3a497
ssdeep: 12288:TQ9U0sb9DG0JlCCr9pKkrWARRwdoHa6+dAp/X:TQ+HCuMkrWTo3P
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2011
Assembly Version: 1.3.0.1
InternalName: Natasha.exe
FileVersion: 1.3.0.9
CompanyName:
LegalTrademarks:
Comments:
ProductName: D.A.F.P.H
ProductVersion: 1.3.0.9
FileDescription: Device Association Framework Provider Host
OriginalFilename: Natasha.exe

Malware.AI.3096603105 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.DataStealer.1.0A1B7F9F
FireEyeGeneric.mg.c638e8327f9bbf1b
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderGeneric.DataStealer.1.0A1B7F9F
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
RisingSpyware.Agent!8.C6 (TFE:dGZlOg2Pnk38uyQBOQ)
Ad-AwareGeneric.DataStealer.1.0A1B7F9F
EmsisoftGeneric.DataStealer.1.0A1B7F9F (B)
F-SecureHeuristic.HEUR/AGEN.1134525
DrWebTrojan.PWS.Siggen2.62119
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosML/PE-A
IkarusTrojan.MSIL.Vmprotect
GDataMSIL.Trojan-Stealer.DataStealer.B
AviraHEUR/AGEN.1134525
ArcabitGeneric.DataStealer.1.0A1B7F9F
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.D9!ml
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.34590.Lu0@aKiT6L
ALYacGeneric.DataStealer.1.0A1B7F9F
MAXmalware (ai score=80)
MalwarebytesMalware.AI.3096603105
ESET-NOD32a variant of MSIL/Spy.Agent.DAT
SentinelOneStatic AI – Malicious PE
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.27f9bb

How to remove Malware.AI.3096603105?

Malware.AI.3096603105 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment