Malware

How to remove “Malware.AI.3128106696”?

Malware Removal

The Malware.AI.3128106696 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3128106696 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3128106696?


File Info:

name: 234BEBC38F153F6C16FA.mlw
path: /opt/CAPEv2/storage/binaries/2bad9a73b445931f9b021d11ef218d502af8c07765f2a4faa664037c63628ed7
crc32: E8007798
md5: 234bebc38f153f6c16fa73f4d4ca1179
sha1: ee19b4428bc3e43a36e6654105672441915fe6a8
sha256: 2bad9a73b445931f9b021d11ef218d502af8c07765f2a4faa664037c63628ed7
sha512: 6ef735179c4dc45861c3d2c3092dfd1944571c283057cfb1a4857e1a70c14e490d5ebe93d573d57c6dd767a0eea1f15a199879217384f4c30f650d4167dc71c2
ssdeep: 6144:Pv2mt+/7OdThwus5emGSwkznfdyWRM5AC1gc:j+/7zemjznAW65RR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122245A2EF764B332F14641B81549169090BDF43635866C2AE7C19F0EBAE2DC7E6313A7
sha3_384: 1f2a49e09842757a0215f93ef8ebf5d0398ef384af5e1cc37f815a970b256e443fc52fb6ce971d1c99a92980b933de7f
ep_bytes: 68a01d4000e8eeffffff000000000000
timestamp: 2011-05-12 14:58:09

Version Info:

CompanyName: TeamViewer GmbH
FileDescription: TeamViewer Remote Control Application
FileVersion: 6.0.10511.0
InternalName: TeamViewer
LegalCopyright: TeamViewer GmbH
LegalTrademarks: TeamViewer
OriginalFilename: TeamViewer.exe
PrivateBuild: TeamViewer Remote Control Application
ProductName: TeamViewer
ProductVersion: 6.0
Translation: 0x0809 0x04b0

Malware.AI.3128106696 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Clicker.3
FireEyeGeneric.mg.234bebc38f153f6c
CAT-QuickHealTrojan.VB.Gen
ALYacGen:Variant.Clicker.3
ZillyaBackdoor.Bifrose.Win32.98691
Sangfor[MICROSOFT VISUAL BASIC 5.0]
K7AntiVirusTrojan ( 002571681 )
AlibabaBackdoor:Win32/Bifrose.a90201ab
K7GWTrojan ( 002571681 )
Cybereasonmalicious.38f153
BitDefenderThetaGen:NN.ZevbaF.34806.nm2@aKBXEQki
VirITTrojan.Win32.Agent.BZIC
CyrenW32/Zbot.CE.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.GIN
ClamAVWin.Dropper.Zeus-9864303-0
KasperskyBackdoor.Win32.Bifrose.fkju
BitDefenderGen:Variant.Clicker.3
NANO-AntivirusTrojan.Win32.Zbot.doaqa
AvastWin32:Inject-AJO [Trj]
RisingBackdoor.Bifrose!8.B24 (CLOUD)
Ad-AwareGen:Variant.Clicker.3
EmsisoftGen:Variant.Clicker.3 (B)
ComodoTrojWare.Win32.Trojan.Zbot.~bvsh@40gkqt
DrWebBackDoor.Cybergate.1
VIPREGen:Variant.Clicker.3
McAfee-GW-EditionBehavesLike.Win32.Virut.dh
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Agent-SHP
APEXMalicious
JiangminTrojanSpy.Zbot.cxdk
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Zbot.fbu
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Clicker.3
ViRobotTrojan.Win32.A.Zbot.516096
GDataGen:Variant.Clicker.3
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R8949
Acronissuspicious
McAfeePWS-Zbot.gen.hx
VBA32Trojan.VB.01391
MalwarebytesMalware.AI.3128106696
TencentMalware.Win32.Gencirc.10b55ad3
YandexTrojan.GenAsa!WDx5IpGbDiQ
IkarusTrojan-Spy.Win32.SpyEyes
FortinetW32/Injector.GKF!tr
AVGWin32:Inject-AJO [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3128106696?

Malware.AI.3128106696 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment