Malware

Malware.AI.3112235746 removal tips

Malware Removal

The Malware.AI.3112235746 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3112235746 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to restart the guest VM
  • Wrote 512 bytes to physical drive potentially indicative of overwriting the Master Boot Record (MBR)
  • Attempted to write directly to a physical drive
  • Operates on local firewall’s policies and settings
  • Accessed credential storage registry keys

How to determine Malware.AI.3112235746?


File Info:

name: EF71371D10A301046D1E.mlw
path: /opt/CAPEv2/storage/binaries/a9b3710d13957ac61287d5bd3535fb2c70bbe392cf18b8ecc939719c299aa965
crc32: B785CB8B
md5: ef71371d10a301046d1ec00062ffe6f7
sha1: 1c849fdafaa845e23a702f65981acecf63ac7f3d
sha256: a9b3710d13957ac61287d5bd3535fb2c70bbe392cf18b8ecc939719c299aa965
sha512: 5a8e8a648aeaf2fde2a2728bbcfc5d962911d25acb1065f0babf35a2c169470578bd299ecc43de8f6ea5b390807ae95fe2da1e4d2d6962e8822457ff4e7473b9
ssdeep: 192:2hGt8dnPYyCGi1dFjWLKKaKd0kQm93Rj:2CePYyTi30RVB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5E18E7FF6A944F3C2C64437234CCE2296988C948FFA66006BFE1ADB9DF51505B0A651
sha3_384: f66bbad061f67c7a60ba219ab0384b134d604aa8df6e244ee23133af928a88d33c867c8c83f2f046b3c95e0e046093aa
ep_bytes: 60be15a040008dbeeb6fffff5783cdff
timestamp: 2021-05-14 00:36:03

Version Info:

0: [No Data]

Malware.AI.3112235746 also known as:

LionicTrojan.Win32.DiskWriter.4!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
McAfeeArtemis!EF71371D10A3
CylanceUnsafe
SangforTrojan.Win32.DiskWriter.gen
K7AntiVirusTrojan ( 0057d6891 )
BitDefenderGen:Variant.Symmi.83302
K7GWTrojan ( 0057d6891 )
Cybereasonmalicious.d10a30
CyrenW32/Trojan.LOUN-9160
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KillDisk.NCD
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.DiskWriter.gen
NANO-AntivirusTrojan.Win32.KillDisk.ivwded
MicroWorld-eScanGen:Variant.Symmi.83302
AvastFileRepMalware [Trj]
RisingTrojan.KillDisk!8.C4C (CLOUD)
Ad-AwareGen:Variant.Symmi.83302
ZillyaTrojan.KillDisk.Win32.288
TrendMicroTROJ_GEN.R002C0PC222
McAfee-GW-EditionBehavesLike.Win32.Generic.zc
FireEyeGeneric.mg.ef71371d10a30104
EmsisoftGen:Variant.Symmi.83302 (B)
IkarusTrojan.Win32.KillDisk
GDataGen:Variant.Symmi.83302
JiangminTrojan.DiskWriter.aez
ArcabitTrojan.Symmi.D14566
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win.Generic.C4513734
VBA32BScope.Trojan.DiskWriter
ALYacGen:Variant.Symmi.83302
MAXmalware (ai score=81)
MalwarebytesMalware.AI.3112235746
TrendMicro-HouseCallTROJ_GEN.R002C0PC222
YandexTrojan.DiskWriter!jFYw9P/dNM4
MaxSecureTrojan.Malware.73853521.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaE.34638.amGfayz55Fn
AVGFileRepMalware [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3112235746?

Malware.AI.3112235746 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment