Malware

How to remove “Malware.AI.3217865479”?

Malware Removal

The Malware.AI.3217865479 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3217865479 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Malware.AI.3217865479?


File Info:

name: 995877A3C18450F5FE93.mlw
path: /opt/CAPEv2/storage/binaries/d9c7d3392c1ee1b924601977d119173f417aa4a126f4900fe51f447688597176
crc32: 9524FD97
md5: 995877a3c18450f5fe931997f9cf094b
sha1: 29648f4dd51170ef06e01314ef79b5885281df6d
sha256: d9c7d3392c1ee1b924601977d119173f417aa4a126f4900fe51f447688597176
sha512: 44b9f9844fe9920ba59c09f06512f3119fd77044d3ceff58cc7a883c1cb19e4eed7a4a3be6d8816da0e63225f9dfd56a7c4e4d31872174f4961446d97fb32d61
ssdeep: 6144:NQV9aeyJha0WWHLBcVAhql5AOOZWgv2maZ:qVIhN7rBcVAC5dgvk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F848F927561C5B3E25137B5C8A8FB314959A4213F33C6CBAF5436AEC9B12C019336FA
sha3_384: c1baf7eec8844bb59ae0db8ac4496b67693245dd01049381f19552767a9d85dae615048d1699f43c97b408d354b1fa42
ep_bytes: e83a920000e989feffffff35040d4400
timestamp: 2015-04-06 19:46:26

Version Info:

CompanyName: InstallationSafe
FileDescription: Setup Installer
FileVersion: 1.0.0.1
InternalName: setup.exe
LegalCopyright: Copyright (C) 2015
OriginalFilename: setup.exe
ProductName: Setup Installer
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Malware.AI.3217865479 also known as:

LionicRiskware.Win32.AddGazelle.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Bundler.AddGazelle.A
FireEyeApplication.Bundler.AddGazelle.A
CAT-QuickHealTrojan.IGENERIC
ALYacApplication.Bundler.AddGazelle.A
CylanceUnsafe
ZillyaTool.Bundler.Win32.5222
K7AntiVirusAdware ( 004bcfd51 )
K7GWAdware ( 004bcfd51 )
Cybereasonmalicious.3c1845
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AdGazelle.F potentially unwanted
APEXMalicious
BitDefenderApplication.Bundler.AddGazelle.A
NANO-AntivirusRiskware.Win32.Adw.dtfots
SUPERAntiSpywarePUP.Bundler/Variant
AvastWin32:Malware-gen
Ad-AwareApplication.Bundler.AddGazelle.A
EmsisoftApplication.Bundler.AddGazelle.A (B)
ComodoApplication.Win32.AdGazelle.FD@5pkjs7
DrWebAdware.Downware.12512
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTROJ_GEN.R002C0PL321
McAfee-GW-EditionPUP-XAL-NT
SophosGeneric PUA CJ (PUA)
IkarusPUA.AdGazelle
GDataApplication.Bundler.AddGazelle.A
AviraADWARE/AdGazelle.Gen
Antiy-AVLTrojan/Generic.ASMalwS.151501C
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Generic.R142591
McAfeePUP-XAL-NT
MAXmalware (ai score=77)
VBA32Adware.Downware
MalwarebytesMalware.AI.3217865479
TrendMicro-HouseCallTROJ_GEN.R002C0PL321
RisingTrojan.Generic@ML.100 (RDML:vpkO12w1QZ7srOCLpP4dYA)
YandexRiskware.Agent!nw465m0T76o
eGambitUnsafe.AI_Score_96%
FortinetRiskware/AdGazelle
BitDefenderThetaGen:NN.ZexaF.34084.xu0@aeyJkOgi
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.3217865479?

Malware.AI.3217865479 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment