Malware

How to remove “Malware.AI.3167284325”?

Malware Removal

The Malware.AI.3167284325 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3167284325 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3167284325?


File Info:

name: 79936004052A8461EDDF.mlw
path: /opt/CAPEv2/storage/binaries/7672b931a1ee3a3bee527d69870628ed2d46b117df2425f6a11db1765320ddba
crc32: 9FB78BC0
md5: 79936004052a8461eddf914667b1d1a7
sha1: cf3d423b05413e6c043539c7eac74102776b78ac
sha256: 7672b931a1ee3a3bee527d69870628ed2d46b117df2425f6a11db1765320ddba
sha512: fefe314db7fdda7e9cc830457395d9a684c0b77a144c06aa3fc1bd6a6ca2b7054e30e749b7d783e2c18b414a570633e9ab887f73309a633e56d089ee9104c3c6
ssdeep: 24576:Bs5UCG5T3fbu4NHLQpYZNbVlOhPZqegbsUb:SoLFLtkhPZqbb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106F42353EAD288B1C05186708C26E6019A7B7B3A2D395D24F29C1FDE7F332518D5A7E3
sha3_384: d6e4dc45e94aed4cfc483ee50cf58635b8f9e157541f11019e335e47287a0bf2c608351fc0b3cf669983ea1d6b7e8f84
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: 此安装程序由 Inno Setup 构建。
CompanyName: 北京神州泰岳软件股份有限公司
FileDescription: Ultra-IGA SSO Agent client-20190801注册表方式登录控件 Setup
FileVersion:
LegalCopyright:
ProductName: Ultra-IGA SSO Agent client-20190801注册表方式登录控件
ProductVersion:
Translation: 0x0804 0x0000

Malware.AI.3167284325 also known as:

LionicTrojan.Win32.Bulz.4!c
MicroWorld-eScanGen:Variant.Bulz.76711
FireEyeGen:Variant.Bulz.76711
ALYacGen:Variant.Bulz.76711
CylanceUnsafe
SangforRiskware.Win32.Ymacco.AA76
K7AntiVirusTrojan ( 000ab3041 )
AlibabaPacked:Win32/Generic.61c160e6
K7GWTrojan ( 000ab3041 )
CyrenW32/Trojan.XDZD-3699
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Packed.Autoit.E.Gen suspicious
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Dropped-111
BitDefenderGen:Variant.Bulz.76711
AvastWin32:Malware-gen
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Otorun-13
McAfee-GW-EditionBehavesLike.Win32.BadFile.bc
EmsisoftGen:Variant.Bulz.76711 (B)
Antiy-AVLTrojan/Generic.ASCommon.168
MicrosoftProgram:Win32/Ymacco.AA76
GDataGen:Variant.Bulz.76711
AhnLab-V3Malware/Win.Generic.R373741
McAfeeArtemis!79936004052A
MAXmalware (ai score=89)
VBA32Trojan.Occamy
MalwarebytesMalware.AI.3167284325
TrendMicro-HouseCallMal_Otorun-13
FortinetRiskware/Mal_Otorun
AVGWin32:Malware-gen
Cybereasonmalicious.4052a8

How to remove Malware.AI.3167284325?

Malware.AI.3167284325 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment