Malware

Malware.AI.3281721140 removal guide

Malware Removal

The Malware.AI.3281721140 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3281721140 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Attempts to modify proxy settings

How to determine Malware.AI.3281721140?


File Info:

name: 412C6DB7FC29CF2C89C2.mlw
path: /opt/CAPEv2/storage/binaries/6c67794dcbfaf403724324535a9c34ba7274db3eb4580b6d6be285454f1f378e
crc32: 624CB141
md5: 412c6db7fc29cf2c89c219a9af5edba1
sha1: 4bf56e9bf5f1651bb124ef544deee68313d9df87
sha256: 6c67794dcbfaf403724324535a9c34ba7274db3eb4580b6d6be285454f1f378e
sha512: 3fb83b0df8d98dcd4607b808dfbf2c1e42910978d7da87203694663d544a014e6d474c0b7c9ed7cb77fc37033b8ec50890cd478d295462348e97f5f6004be33d
ssdeep: 98304:SwHJtX1NElHr7RJyI0MgnpAPQunb72pfvqvm32/V7fGOnE:jHJtX3ElHr7RJaJXunmivJt7fGSE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190060201B50E46E8F87653B8B6AAE1A1F1A160F94B467D1AF16337036F9CA7D00FF641
sha3_384: 98862acf1bd2f9c13998be95a545555fbe079b1bf7a8c5fce446a747cfee22c5477ac7dfb7d07651975e31b120ccb379
ep_bytes: e84f570000e995feffff8bff558bec83
timestamp: 2018-06-06 15:32:28

Version Info:

0: [No Data]

Malware.AI.3281721140 also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.378167
FireEyeGeneric.mg.412c6db7fc29cf2c
ALYacGen:Variant.Bulz.378167
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004e2f011 )
BitDefenderGen:Variant.Bulz.378167
K7GWAdware ( 004e2f011 )
Cybereasonmalicious.7fc29c
BitDefenderThetaGen:NN.ZexaF.34742.VxY@a8eCzdbj
VirITPUP.Win32.Generic.R
CyrenW32/S-15b9ae50!Eldorado
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agent.gen
AlibabaTrojan:Win32/MalwareX.9e0fa4e6
RisingAdware.ENotepad!1.D192 (CLASSIC)
Ad-AwareGen:Variant.Bulz.378167
SophosMal/Generic-S
ZillyaTrojan.Agent.Win32.1781054
McAfee-GW-EditionGenericRXNI-NW!412C6DB7FC29
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Bulz.378167 (B)
JiangminTrojan.Generic.eljwd
AviraHEUR/AGEN.1224291
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.378167
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R363201
McAfeeGenericRXNI-NW!412C6DB7FC29
VBA32Trojan.Agent
MalwarebytesMalware.AI.3281721140
PandaTrj/Genetic.gen
YandexTrojan.Agent!l8LkaoX1R8g
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zusy.360094!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]

How to remove Malware.AI.3281721140?

Malware.AI.3281721140 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment