Malware

What is “Malware.AI.3296221204”?

Malware Removal

The Malware.AI.3296221204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3296221204 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.3296221204?


File Info:

name: 90A69B8982BE30D34D71.mlw
path: /opt/CAPEv2/storage/binaries/6d546d680c42c5e6f410b3f00179b8f5429d036e1ef4e34cde57f2620d24805e
crc32: 22FBE2C1
md5: 90a69b8982be30d34d718841817c21d3
sha1: 5725e75501d43da7223391f6a2a179648706d617
sha256: 6d546d680c42c5e6f410b3f00179b8f5429d036e1ef4e34cde57f2620d24805e
sha512: f7923be8f48cdf4df3b6f46ee983ade09ff4e9e62e158dd4933abebd2d0a6e43b86b288c2bc032d2bd74a0c094ba766b52a1715d2f60305a23694d28007a258d
ssdeep: 196608:oy8rp/6/LD8I4rwz9bJMQ6br+6bikW7/H4dC:r8rt6X1aEb6bS7/Hd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF86334F170EC5EAFA545439C266ACF3A4E47F15CE81286BB4263CFAFE7E144085538A
sha3_384: e26d09083a0edbae0a19a1a350e1a43faa4de13edef642da179bd5d40c3c26d6ce762eb0e1e6492049094eb3ca9cd964
ep_bytes: 60be0020d0008dbe00f06fffc787ec70
timestamp: 2008-12-02 15:41:29

Version Info:

0: [No Data]

Malware.AI.3296221204 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.473
MicroWorld-eScanGen:Variant.Adware.SMSHoax.25
FireEyeGeneric.mg.90a69b8982be30d3
CAT-QuickHealHoax.Archsms.21852
McAfeeArtemis!90A69B8982BE
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforTrojan.Win32.Occamy.C
AlibabaVirTool:Win32/Obfuscator.44b4ea2d
Cybereasonmalicious.982be3
BitDefenderThetaAI:Packer.2C64342220
VirITTrojan.Win32.SMSSend.SF
CyrenW32/Kryptik.DKT.gen!Eldorado
SymantecTrojan.ADH.2
ESET-NOD32a variant of Win32/Kryptik.MOS
ClamAVWin.Adware.Agent-451618
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Adware.SMSHoax.25
NANO-AntivirusRiskware.Win32.ArchSMS.utmvj
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b878ec
Ad-AwareGen:Variant.Adware.SMSHoax.25
EmsisoftGen:Variant.Adware.SMSHoax.25 (B)
ComodoMalware@#1ped4gpaheqeb
ZillyaTrojan.ArchSMS.Win32.377
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-R + Mal/EncPk-ZC
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Adware.SMSHoax.25
JiangminHoax.ArchSMS.loa
eGambitGeneric.Malware
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.323628A
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.AI.3296221204
APEXMalicious
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!K9QWYfIJ3gg
Ikarusnot-a-virus:Hacktool.SMSHoax
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen

How to remove Malware.AI.3296221204?

Malware.AI.3296221204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment