Malware

About “Malware.AI.3228395977” infection

Malware Removal

The Malware.AI.3228395977 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3228395977 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Malware.AI.3228395977?


File Info:

name: E00A4941039EC630C6B3.mlw
path: /opt/CAPEv2/storage/binaries/bd4ba624e850bd6b3e0c2d481eca72a9d1891298d25b2d23c18c94196d4db649
crc32: E635F7C0
md5: e00a4941039ec630c6b347917323ed15
sha1: f93044ba063a4e8be5326e8bc51fa9ba6198de0b
sha256: bd4ba624e850bd6b3e0c2d481eca72a9d1891298d25b2d23c18c94196d4db649
sha512: d8e928476ed6ef07d171c82ebf18f70576e9874f14b50725bbb2cb36c4816cadd85a5077917a5756acab4853427f9493bf0cb6ed14a0898b11762f93809141fe
ssdeep: 6144:dXaAYAT908PCRLwcqcWhf6VPexvowGiT7uBXPuzS4Gz8k87CT3:dX1JPCaj5QPWDMu+4t7Cj
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T12B4423AC53CE8980CE9236766FCB5325B278D342CD15EAADCA482C464F77F872E415D4
sha3_384: 6529eba000bda8452ad93c4cb21a1b1efac34bb25844a9de51436331634607b18777db29b1ae5e29ae99b603d9dc7884
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-12-06 15:24:55

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: test5.exe
LegalCopyright:
OriginalFilename: test5.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Malware.AI.3228395977 also known as:

LionicTrojan.MSIL.Phny.j!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop19.12583
MicroWorld-eScanTrojan.GenericKD.47580513
McAfeeArtemis!E00A4941039E
CylanceUnsafe
K7AntiVirusTrojan ( 0058970e1 )
AlibabaRansom:MSIL/Pucrpt.f164854a
K7GWTrojan ( 0058970e1 )
Cybereasonmalicious.a063a4
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ADGR
TrendMicro-HouseCallRansom_Phny.R002C0DL621
Paloaltogeneric.ml
ClamAVWin.Packed.njRAT-7474448-0
KasperskyHEUR:Trojan-Ransom.MSIL.Phny.gen
BitDefenderTrojan.GenericKD.47580513
AvastWin64:DropperX-gen [Drp]
TencentMsil.Trojan.Phny.Afha
Ad-AwareTrojan.GenericKD.47580513
EmsisoftTrojan.GenericKD.47580513 (B)
TrendMicroRansom_Phny.R002C0DL621
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e00a4941039ec630
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Bladabindi.U9YWWG
WebrootW32.Dropper.Gen
AviraHEUR/AGEN.1122383
MAXmalware (ai score=81)
ArcabitTrojan.Generic.D2D60561
MicrosoftVirTool:Win32/Pucrpt.B!MTB
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4623747
VBA32TrojanRansom.MSIL.Phny
ALYacTrojan.GenericKD.47580513
MalwarebytesMalware.AI.3228395977
APEXMalicious
IkarusTrojan.MSIL.Krypt
FortinetMSIL/Kryptik.ADGR!tr
AVGWin64:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.3228395977?

Malware.AI.3228395977 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment