Malware

Malware.AI.3305750983 malicious file

Malware Removal

The Malware.AI.3305750983 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3305750983 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Malware.AI.3305750983?


File Info:

name: 38AB05D5D54F9DCF3FBD.mlw
path: /opt/CAPEv2/storage/binaries/62de3f2e175a39e55a9730139e0f9cd540c9c3c9a3dd06cc765989229bae9366
crc32: 88FCF690
md5: 38ab05d5d54f9dcf3fbd216414beedd2
sha1: 06e89245067805994cef8960335f197efb587f49
sha256: 62de3f2e175a39e55a9730139e0f9cd540c9c3c9a3dd06cc765989229bae9366
sha512: bc35ed8130fcf5f4e87ed8c1bca6233251a4a4cf1c2766e60892614c73234dcdf5cf82a8f42dcb6bcc93e6b47d7fc0e99e856345d978b8959db9dfefeb40d77d
ssdeep: 1536:jh8Zc0c2TeH53F/y8fnFZTd6Ue6IWVvmfYC+zyl+U8/6O:98Zc0hqH53F/y0nzTd6UjIWVvn+o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF34C06395A671CEF8B29F3E81E61D03CB4AB241436F945D25C2114F0904BC76E9FFA5
sha3_384: 4ed5958fd622ee095de782dd1082ed7e75bb9b05d1c2d384b0f6921b2b2c7351254ab0960076de4a3be3ea2ea9738e7e
ep_bytes: 558bec83ec24893424687c4940008914
timestamp: 2002-02-24 13:42:10

Version Info:

CompanyName: Macromedia, Inc.
FileDescription: Macromedia Flash Player 7.0 r19
FileVersion: 7,0,19,0
InternalName: Macromedia Flash Player 7.0
LegalCopyright: Copyright © 1996-2003 Macromedia, Inc.
LegalTrademarks: Macromedia Flash Player
OriginalFilename: SAFlashPlayer.exe
ProductName: Shockwave Flash
ProductVersion: 7,0,19,0
Translation: 0x0409 0x04b0

Malware.AI.3305750983 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BPRR
CAT-QuickHealW32.Virut.G
ALYacTrojan.Agent.BPRR
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0047bf9a1 )
K7GWTrojan ( 0047bf9a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Virus.Virut.gen
VirITWin32.Scribble.AB
CyrenW32/Ramnit.H.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32Win32/Virut.NBP
APEXMalicious
ClamAVWin.Packed.Ramnit-9946126-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BPRR
NANO-AntivirusTrojan.Win32.Rmnet.ddidny
SUPERAntiSpywareTrojan.Agent/Gen-FiviGen
AvastWin32:Vitro [Inf]
TencentTrojan.Win32.Ramnit.a
Ad-AwareTrojan.Agent.BPRR
EmsisoftTrojan.Agent.BPRR (B)
ComodoTrojWare.Win32.Spy.Zbot.WEBA@4min4f
DrWebTrojan.Rmnet.1
ZillyaTrojan.Lebag.Win32.229
TrendMicroTROJ_RAMNIT.SMD
McAfee-GW-EditionBehavesLike.Win32.ZBot.dz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.38ab05d5d54f9dcf
SophosML/PE-A + W32/Ramnit-BM
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BPRR
JiangminTrojan/Lebag.iq
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=85)
ArcabitTrojan.Agent.BPRR
ViRobotWorm.Win32.A.Net-Koobface.197632
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Krap.R27995
McAfeePWS-Zbot.gen.di
VBA32Malware-Cryptor.Win32.General.4
MalwarebytesMalware.AI.3305750983
TrendMicro-HouseCallTROJ_RAMNIT.SMD
RisingWorm.Win32.Koobface.ji (CLASSIC)
YandexTrojan.XPACK!PGM4bjzWZuY
IkarusVirus.Win32.Heur
FortinetW32/CoinMiner.F
BitDefenderThetaAI:FileInfector.C2A5779617
AVGWin32:Vitro [Inf]
Cybereasonmalicious.5d54f9
PandaTrj/Pck_Pretorx.A

How to remove Malware.AI.3305750983?

Malware.AI.3305750983 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment