Malware

What is “Malware.AI.3269895475”?

Malware Removal

The Malware.AI.3269895475 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3269895475 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3269895475?


File Info:

name: 9D773A8A08E63C4D67F9.mlw
path: /opt/CAPEv2/storage/binaries/ba3d2887d16909529048bdb6e7859f80e363c46216b84d634d775354d012e9a9
crc32: 5E1D0528
md5: 9d773a8a08e63c4d67f9039cb109d18b
sha1: 54679443b2ef244f099dd9b55bc0ddc3e172981f
sha256: ba3d2887d16909529048bdb6e7859f80e363c46216b84d634d775354d012e9a9
sha512: b99622ac56951f355f2eb950a571d68981e8acf35d73d85b95b11a54ea25bb54b5c8c1ca42284c2f01535aa91ca9921e989f51d0d28e31c15041bb5fb9e01def
ssdeep: 24576:QGmZKMDi1W7bwDIKxzccaSL++aGJFayKZ:lmJDfIDIKsm++a6cyKZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13665D0127685DF31E1AF0635DA68D6B0567FBC20DF2187CB63803E1A7A706C1A935B27
sha3_384: 60fd226ac4db14a5f418a529bcbc9e74d34b2725795498fdd5598cdfa2e4fa46cb527bda17d5c684c61979576d3ee791
ep_bytes: e8e2090000e978feffffcccccccccccc
timestamp: 2021-01-26 05:50:15

Version Info:

CompanyName: Adobe Inc.
EnglishName: English
FileDescription: Adobe Reader and Acrobat Manager Helper
FileVersion: 1.824.42.0176
LanguageId: 0409
LegalCopyright: Copyright © 2020 Adobe Inc. All rights reserved.
ProductVersion: 1.824.42.0176
Translation: 0x0409 0x000b

Malware.AI.3269895475 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
ALYacWin32.Expiro.Gen.7
MalwarebytesMalware.AI.3269895475
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Expiro.AU.gen!Eldorado
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.CY
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
TrendMicroVirus.Win32.EXPIRO.JMA
McAfee-GW-EditionBehavesLike.Win32.Sality.tm
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.9d773a8a08e63c4d
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftTrojan:Script/Phonzy.B!ml
GoogleDetected
MAXmalware (ai score=82)
VBA32Trojan.Sabsik.TE
PandaW32/Moyv.A
RisingTrojan.Generic@AI.93 (RDML:17w/p6DRWTHMflBY+aXPHQ)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
BitDefenderThetaGen:NN.ZexaF.36348.Cv0@a0IUiwai
Cybereasonmalicious.3b2ef2
DeepInstinctMALICIOUS

How to remove Malware.AI.3269895475?

Malware.AI.3269895475 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment