Malware

Malware.AI.3219865997 removal instruction

Malware Removal

The Malware.AI.3219865997 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3219865997 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.3219865997?


File Info:

name: 30296B53B9068447A8C3.mlw
path: /opt/CAPEv2/storage/binaries/3b6bb4c126edabbce0092392761e38cc6ae391c808827d29d37b6f8589912088
crc32: E1FB496D
md5: 30296b53b9068447a8c3ee3082f48533
sha1: ffb336f89b3f93c5b8ffe78f7947c3cb9f61fb4d
sha256: 3b6bb4c126edabbce0092392761e38cc6ae391c808827d29d37b6f8589912088
sha512: c9fcfb4fc431cb11d807db5b8566cb7647728b46a9b832004a8f3d69e00e05f66d0bce1a8ec1852b3495ee0701485a7fe8a30e9a034901a3d0d4e384e0b9bd5e
ssdeep: 192:+Ijb8TCA4xYHG1mMfIJqUbhwKpduPjXJKc4CxIqQQZG25UlWLo:FcWvzwviKeZ1GaNo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8625C6B7AC7DF93C2A64B3164B6C7D063347479310243BE7EB71A2DEE23E569841109
sha3_384: 1649410f988f1e53fce8cd4b45fda8f6693f43e3d3da6ac16c3d12371aaddd13f5fc654114237ae9945206065904d73e
ep_bytes: 60be158040008dbeeb8fffff57eb0b90
timestamp: 2004-05-20 05:59:45

Version Info:

0: [No Data]

Malware.AI.3219865997 also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanGen:Variant.Ursu.384261
FireEyeGeneric.mg.30296b53b9068447
CAT-QuickHealTrojanDownloader.Upatre.A6
SkyhighBehavesLike.Win32.Downloader.lh
McAfeeArtemis!30296B53B906
Cylanceunsafe
ZillyaDownloader.Upatre.Win32.80315
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Waski.732b4b8f
K7GWTrojan ( 0040f7411 )
K7AntiVirusTrojan ( 0040f7411 )
BitDefenderThetaGen:NN.ZexaF.36802.amHfaWbrproi
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
AvastWin32:Waski-C [Cryp]
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.pef
BitDefenderGen:Variant.Ursu.384261
NANO-AntivirusTrojan.Win32.DownLoad3.csruhz
TencentMalware.Win32.Gencirc.11bdbb29
EmsisoftGen:Variant.Ursu.384261 (B)
F-SecureTrojan.TR/Downloader.Gen7
VIPREGen:Variant.Ursu.384261
TrendMicroTROJ_UPATRE.SM37
Trapminesuspicious.low.ml.score
SophosTroj/Kryptik-CF
MAXmalware (ai score=87)
JiangminTrojan/Bublik.gqa
GoogleDetected
AviraTR/Downloader.Gen7
VaristW32/Upatre.RY.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Waski
Kingsoftmalware.kb.b.998
MicrosoftTrojan:Win32/Waski.A!MTB
ArcabitTrojan.Ursu.D5DD05
ViRobotTrojan.Win.Z.Ursu.15028
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.pef
GDataWin32.Trojan.PSE.1KWQPUE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Upatre.C5602831
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Ursu.384261
MalwarebytesMalware.AI.3219865997
PandaTrj/Genetic.gen
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.DL.Upatre!1yls1EhEfgs
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.CF!tr
AVGWin32:Waski-C [Cryp]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Waski.A

How to remove Malware.AI.3219865997?

Malware.AI.3219865997 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment