Malware

Should I remove “Malware.AI.3120010537”?

Malware Removal

The Malware.AI.3120010537 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3120010537 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Collects information about installed applications

How to determine Malware.AI.3120010537?


File Info:

name: 58603F5345BFE580BB45.mlw
path: /opt/CAPEv2/storage/binaries/0a85c287059db1fe1243ce14f62ab2be2adf7a08709e67b58cc77dbfb60f9844
crc32: 949D37E0
md5: 58603f5345bfe580bb45dadd3ccf58d1
sha1: 56f0421afeb743a2ca5f3ebb054061de65c70a44
sha256: 0a85c287059db1fe1243ce14f62ab2be2adf7a08709e67b58cc77dbfb60f9844
sha512: cc8e5d8608cc739beff4ee5b382254285ebc3f269a971d7f7808c1149f613db5433efb29314a17db12decb3205b5705a000e6962d1be17be8b43b151f126aa78
ssdeep: 49152:oUypvIdhb2w+CuDmdu6Vx1wVVf8zWAYtF27NrwOPHrueipTQ8oH:oURhbP+CuidzPwL9AB7NrwFG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBA5CF22BF81D172E5D2027456BB5B7F5C3AAA304338C4E3D7901A759D302E2673E7A6
sha3_384: 699182873a4910f168b039248dd508461a1baabdf24807395cbd981b86a02da0065aa1c700fef35629ee91b8b487c566
ep_bytes: e89b060000e97afeffff558bec56ff75
timestamp: 2021-03-08 01:59:01

Version Info:

CompanyName: 四川齐鑫网络科技有限公司
FileDescription: 蝴蝶看图
InternalName: 蝴蝶看图
LegalCopyright: Copyright (C) 2020四川齐鑫网络科技有限公司
OriginalFilename: ButflyImgEsh.exe
ProductName: 蝴蝶看图
ProductVersion: 2,0,3,10308
Translation: 0x0804 0x04b0

Malware.AI.3120010537 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31247590
FireEyeGeneric.mg.58603f5345bfe580
CAT-QuickHealPUA.AgentRI.S19235117
CylanceUnsafe
ZillyaAdware.Burden.Win32.5188
SangforVirus_Suspicious.Win32.Sality.bh
K7AntiVirusAdware ( 00571de41 )
AlibabaAdWare:Win32/Softcnapp.5e442914
K7GWAdware ( 00571de41 )
Cybereasonmalicious.afeb74
BitDefenderThetaGen:NN.ZexaF.34114.ew2@a0dAgQdj
VirITWin32.Sality.BI
CyrenW32/Sality.AY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BH potentially unwanted
TrendMicro-HouseCallPE_SALITY.ER
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Burden.gen
BitDefenderTrojan.Generic.31247590
NANO-AntivirusRiskware.Win32.Burden.ivtvui
AvastWin32:Sality [Inf]
TencentPua:AdWare.Win32.Burden.16000060
Ad-AwareTrojan.Generic.31247590
EmsisoftTrojan.Generic.31247590 (B)
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroPE_SALITY.ER
McAfee-GW-EditionBehavesLike.Win32.PUP.vh
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S (PUA)
APEXMalicious
JiangminAdWare.Burden.aul
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34DE6F5
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
ViRobotAdware.Burden.2164072
GDataTrojan.Generic.31247590
CynetMalicious (score: 100)
Acronissuspicious
VBA32Adware.Burden
ALYacTrojan.Generic.31247590
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3120010537
RisingAdware.Agent!1.C1A1 (CLOUD)
IkarusPUA.Softcnapp
FortinetAdware/Softcnapp.BF
AVGWin32:Sality [Inf]

How to remove Malware.AI.3120010537?

Malware.AI.3120010537 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment