Malware

Malware.AI.3191206822 removal

Malware Removal

The Malware.AI.3191206822 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3191206822 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.3191206822?


File Info:

name: 87B1BCB4327B0F58ED11.mlw
path: /opt/CAPEv2/storage/binaries/4b963623c76922b122e21c26e304c411fe877ed093f46673a50091c0590d20f7
crc32: 54144357
md5: 87b1bcb4327b0f58ed119d9a90c3ef00
sha1: c5c820bfc62d8ce073ba8180cc164368059e5c61
sha256: 4b963623c76922b122e21c26e304c411fe877ed093f46673a50091c0590d20f7
sha512: 251e3ae77ddb4e55be325503edf06a4b9779b33354b32aec07f5a6333f31859f5d777a2054daa87d202595bc5dd577a7291b2b7727c04cb0eb75d685a62a6291
ssdeep: 3072:Q6QGP44mC4nR5EmkSpjmEsEKMLtKJvLYDf+GxpWQagi9/yUbIlutGDImKrbEd:80r4cTEPLZDmGxpWQgoUbIl91l
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1C41412D542F8025ED56B0D38A262E1962FB4F3CA0E73F79E64EDA04214C338D6A157F9
sha3_384: 9dc2d16cc89aa067dd3baee5593e80c5834f3738298dbb116be40ddb7f161d1e2b2984f0f00f0d812e3793076380d30d
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-12-05 09:57:13

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: sshnet
FileVersion: 1.0.0.0
InternalName: sshnet.exe
LegalCopyright: Copyright © 2017
LegalTrademarks:
OriginalFilename: sshnet.exe
ProductName: sshnet
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3191206822 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.61072761
FireEyeGeneric.mg.87b1bcb4327b0f58
ALYacTrojan.GenericKD.61072761
CylanceUnsafe
SangforBackdoor.Msil.Sshnet.Vtk8
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:MSIL/SSHNet.74daca11
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fc62d8
BitDefenderThetaGen:NN.ZemsilF.34806.mm2@a4J4L@j
SymantecTrojan.Gen.2
ESET-NOD32MSIL/Agent.TPI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Mikey-9958102-0
KasperskyHEUR:Backdoor.MSIL.SSHNet.gen
BitDefenderTrojan.GenericKD.61072761
AvastFileRepMalware [Misc]
TencentMalware.Win32.Gencirc.120223b6
Ad-AwareTrojan.GenericKD.61072761
VIPRETrojan.GenericKD.61072761
TrendMicroTROJ_GEN.R06BC0PGU22
McAfee-GW-EditionTrojan-FRSR!87B1BCB4327B
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
JiangminBackdoor.MSIL.coji
WebrootW32.Malware.Gen
AviraTR/Agent.mpfqf
Antiy-AVLTrojan/Generic.ASMalwS.8195
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.Z.Sshnet.197976
GDataTrojan.GenericKD.61072761
CynetMalicious (score: 99)
AhnLab-V3Backdoor/Win.SSHNet.C5216219
McAfeeTrojan-FRSR!87B1BCB4327B
MAXmalware (ai score=82)
MalwarebytesMalware.AI.3191206822
TrendMicro-HouseCallTROJ_GEN.R06BC0PGU22
RisingBackdoor.SSHNet!8.1176D (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGFileRepMalware [Misc]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.3191206822?

Malware.AI.3191206822 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment