Malware

Malware.AI.3281486976 information

Malware Removal

The Malware.AI.3281486976 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3281486976 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

Related domains:

trick.matchoatmeal.icu
fuss.wavesfork.online
wpad.local-net

How to determine Malware.AI.3281486976?


File Info:

name: C93FCA9A26967F9F772D.mlw
path: /opt/CAPEv2/storage/binaries/22f5e3fecbf639ee614bf13ca7fb8ae420d5074518c6923ec60d738f2419858e
crc32: 5F9E4490
md5: c93fca9a26967f9f772d2fa2d1a38834
sha1: 31ccd2d1c7708bc898c83aa475701d091cce5e23
sha256: 22f5e3fecbf639ee614bf13ca7fb8ae420d5074518c6923ec60d738f2419858e
sha512: 94e0046524d611ac43bf8aa67f361cb7479df5e1c560d10bdb1241391da492db4402d17c8a419173407fccead40231cbd19442fc75552fff5887df6d41ee1d89
ssdeep: 24576:/rQ/bKhDdFSj6tepi5XZysW/tfmvIFmFKYklejPVGAUKNMnuzUz:8Aer+S2K0DohJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18DE533B872D5F329C5EB0E3F4EA069CE035DA79B411C0DEF57A8250D95383CBD245AA2
sha3_384: a14c799ec6b7a0f610c983b1a4dd12d5a5c915cee902e5a99a74ec14827c856c6f6cc2412bf73a1d4e17879ae6a7f84b
ep_bytes: 558bec81ec2c010000578b45f42b45f4
timestamp: 2016-07-27 12:50:40

Version Info:

LegalCopyright: ©Odunariythoi aremp
OriginalFilename: sugoise.exe
ProductVersion: 2.9.9.0
InternalName: SUGOISE.EXE
ProductName: SUGOISE
FileVersion: 2.9.9.0
CompanyName: ©Odunariythoi aremp
Translation: 0x0409 0x04e4

Malware.AI.3281486976 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.StartSurf.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17867
MicroWorld-eScanApplication.Agent.ERH
FireEyeGeneric.mg.c93fca9a26967f9f
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacApplication.Agent.ERH
CylanceUnsafe
ZillyaAdware.DownloadHelper.Win32.4634
K7AntiVirusTrojan ( 005410101 )
AlibabaAdWare:Win32/Kryptik.ad01e68d
K7GWTrojan ( 005410101 )
Cybereasonmalicious.a26967
BitDefenderThetaGen:NN.ZexaF.34294.8A0@aae6Qwmi
CyrenW32/Trojan.LEDR-4389
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMFB
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderApplication.Agent.ERH
NANO-AntivirusTrojan.Win32.Vittalia.fjudll
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10cd1b26
Ad-AwareApplication.Agent.ERH
SophosGeneric PUA DB (PUA)
ComodoMalCrypt.Indus!@1qrzi1
TrendMicroTROJ_GEN.R002C0PKM21
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.vz
EmsisoftApplication.Agent.ERH (B)
IkarusPUA.Dlhelper
GDataApplication.Agent.ERH
JiangminAdWare.DownloadHelper.cfd
Antiy-AVLTrojan/Generic.ASMalwS.28C514A
MicrosoftProgram:Win32/Ymacco.AA22
AhnLab-V3PUP/Win32.Helper.R242305
Acronissuspicious
McAfeePacked-FKC!C93FCA9A2696
VBA32BScope.Adware.DownloadHelper
MalwarebytesMalware.AI.3281486976
APEXMalicious
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.DownloadHelper!thMsS42Lups
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GMFB!tr
AVGWin32:Adware-gen [Adw]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.3281486976?

Malware.AI.3281486976 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment