Malware

How to remove “Malware.AI.3141363965”?

Malware Removal

The Malware.AI.3141363965 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3141363965 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Malware.AI.3141363965?


File Info:

name: FF86E0D63CFBE1AED5CF.mlw
path: /opt/CAPEv2/storage/binaries/5449e8d901ba7f2e5e21e2a785eced8f124158b414383c55e3f7c5bf2d588c51
crc32: 0B629DDB
md5: ff86e0d63cfbe1aed5cf5a088f642bc9
sha1: f5584ad0c2f211a1c2b9e0d2be82b6ad872bbf57
sha256: 5449e8d901ba7f2e5e21e2a785eced8f124158b414383c55e3f7c5bf2d588c51
sha512: 0040cfb87b977ec6049ec6c3c7907a73648b9080b0be895dc2885e5d6c7d8de776e301f55ea0a6cfbd5d57ac4f28d0c6fde867179d99f22577e92ed6301fba90
ssdeep: 6144:4WTk73r5isfjGXAne2DAOOfqcWGWCank90oHKdBfw5Ac7uc:4ik73r5TlIicfWCaEHFAc7H
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AE549D21BD914072D53207365AE4CA6A4A2DBCA3075C99EFE7B80ADFCE636C2D531D13
sha3_384: 6653e0c0e8695414a32e4ed2d6fdaaabdf031ff28e84bb74240557e5c94a1f7322160c3fda4277ccd698148fa2242f81
ep_bytes: e8d7050000e974feffff558bec8b4508
timestamp: 2022-05-29 12:40:48

Version Info:

0: [No Data]

Malware.AI.3141363965 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.l!c
MicroWorld-eScanTrojan.GenericKDZ.88851
FireEyeGeneric.mg.ff86e0d63cfbe1ae
ALYacTrojan.GenericKDZ.88851
CylanceUnsafe
SangforTrojan.Win32.Stealer.gen
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/Stealer.4fe6bc90
K7GWTrojan ( 00593a291 )
K7AntiVirusTrojan ( 00593a291 )
CyrenW32/Kryptik.GSY.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HPSR
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKDZ.88851
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10d068cb
Ad-AwareTrojan.GenericKDZ.88851
SophosMal/Generic-S
DrWebTrojan.Inject4.33314
TrendMicroTrojanSpy.Win32.REDLINE.YXCFWZ
McAfee-GW-EditionGenericRXTI-CM!FF86E0D63CFB
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.88851 (B)
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.1CNDVF7
JiangminTrojanSpy.Stealer.vsj
AviraTR/Crypt.Agent.wlada
ArcabitTrojan.Generic.D15B13
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R496171
McAfeeGenericRXTI-CM!FF86E0D63CFB
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3141363965
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCFWZ
RisingTrojan.Kryptik!1.DE43 (CLASSIC)
YandexTrojan.Kryptik!2mpXt88MVIw
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FVGJ!tr
BitDefenderThetaGen:NN.ZexaF.34742.suY@a0ZdyQpi
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Malware.AI.3141363965?

Malware.AI.3141363965 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment