Malware

Malware.AI.3274457717 (file analysis)

Malware Removal

The Malware.AI.3274457717 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3274457717 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3274457717?


File Info:

name: CAE25CA61AD67AF411C0.mlw
path: /opt/CAPEv2/storage/binaries/b5557f45659fc03c44064af26baf50f8b31ec52fc88154460d969082c814866a
crc32: EE19BD79
md5: cae25ca61ad67af411c02b072a01fd1f
sha1: 1bb6f0291cd0c74bba170026c882daff155b2f9f
sha256: b5557f45659fc03c44064af26baf50f8b31ec52fc88154460d969082c814866a
sha512: 4515bdf8b706893458aab63861295b046fd4d477908f539b5aa81cf226253e835f9f7633ae6e413abedb9f5fb5f8fbb589aebf0684f96bce4d8692c8573480a8
ssdeep: 3072:WeNYZdvo/YhoDOiNuhWEbkK3GGSUVMt1U:JNYZdvo/YhoDOiNuhWEbkK3GGSUVqU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166140D6A7943AC26CD4FF87013EECEB34DA791C816C751DE236649DC3A08D58E9703A6
sha3_384: 0062d88b174aced572377be9a9ee77ea4cd8b21cae4866c1842b985414ed6313466cb57e01d8384160f299305bbf87e2
ep_bytes: 68ac124000e8eeffffff000058000000
timestamp: 2010-09-01 09:34:48

Version Info:

Translation: 0x0409 0x04b0
:
FileVersion: 3.42
ProductVersion: 3.42

Malware.AI.3274457717 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner.27450
MicroWorld-eScanGen:Variant.VBKrypt.32
FireEyeGeneric.mg.cae25ca61ad67af4
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.VBKrypt.32
Cylanceunsafe
ZillyaTrojan.VBKrypt.Win32.28666
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 001a29b41 )
AlibabaWorm:Win32/Vobfus.49ff2277
K7GWTrojan ( 001a29b41 )
Cybereasonmalicious.91cd0c
BitDefenderThetaAI:Packer.C7E9108620
VirITTrojan.Win32.Scar.LR
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.TG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1357
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.VBKrypt.32
NANO-AntivirusTrojan.Win32.VBKrypt.covlbz
AvastWin32:AutoRun-BNK [Wrm]
TencentWin32.Worm.Wbna.Dplw
TACHYONTrojan/W32.VB-VBKrypt.208896.B
EmsisoftGen:Variant.VBKrypt.32 (B)
F-SecureWorm:W32/Vobfus.CM
BaiduWin32.Worm.VB.ms
VIPREGen:Variant.VBKrypt.32
TrendMicroWORM_ESFURY.SMA
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
WebrootW32.Worm.Gen
VaristW32/Vobfus.I
AviraTR/Spy.Agent.fla
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Troj.Agent.dl.208896
MicrosoftWorm:Win32/Vobfus.Y
XcitiumTrojWare.Win32.VBKrypt.2@22yg5l
ArcabitTrojan.VBKrypt.32
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.VBKrypt.32
GoogleDetected
AhnLab-V3Win-Trojan/VBKrypt.RP03.X1850
McAfeeDownloader-CJX.gen.j
MAXmalware (ai score=100)
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.3274457717
PandaW32/Vobfus.EY
TrendMicro-HouseCallWORM_ESFURY.SMA
RisingWorm.Vobfus!8.10E (TFE:3:px1TbntNQ5D)
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.5496659.susgen
FortinetW32/VBObfus.BDBD!tr
AVGWin32:AutoRun-BNK [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3274457717?

Malware.AI.3274457717 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment