Malware

Malware.AI.3381331540 removal guide

Malware Removal

The Malware.AI.3381331540 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3381331540 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Unusual version info supplied for binary

How to determine Malware.AI.3381331540?


File Info:

name: 67FFF57BB44D3458B17F.mlw
path: /opt/CAPEv2/storage/binaries/ae1d75a5f87421953372e79c081e4b0a929f65841ed5ea0d380b6289e4a6b565
crc32: 8D0FDFC9
md5: 67fff57bb44d3458b17f0c7a7a45f405
sha1: 08b89a6e2d61239b98235c61a61252254dea91d8
sha256: ae1d75a5f87421953372e79c081e4b0a929f65841ed5ea0d380b6289e4a6b565
sha512: f659c975fab72e952ca02ec88eead0decdae87ab29f9e1cafe25ff2fd272bfd801e8225554b6ec79b4a7c5f87a40905f85ccc5248db2b8857014be7d30c71450
ssdeep: 6144:szXrycaKC2M5nBNip5wjNyYZaHlVfxTV6RrBPLy84IUhRkDTUumNSxQ2+Yeti:e5aKZKjiPMQYQHfZTV6t0/NumeQ2ji
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B874016DB3E28F7EDB4AA1B351E048744725D5603603FB17708802FD9EA27E76691C8B
sha3_384: 05e40e25f118ed927e378a8dee728451d32029edf6767490067474a38ffc06ce120070edfb8995c79431da95635efe27
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-06-23 15:48:03

Version Info:

Translation: 0x0000 0x04b0
Comments: System Manege
CompanyName: Process Maneger
FileDescription: System Worker
FileVersion: 11.25.12.2
InternalName: FileApp.exe
LegalCopyright: Copyright © Maneger Microsoft 2016
LegalTrademarks: System Worker
OriginalFilename: FileApp.exe
ProductName: Maneged
ProductVersion: 11.25.12.2
Assembly Version: 254.11.32.85

Malware.AI.3381331540 also known as:

BkavW32.Common.2D09CFBD
LionicTrojan.Win32.MSILMamut.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILMamut.2737
FireEyeGeneric.mg.67fff57bb44d3458
SkyhighBehavesLike.Win32.Generic.fc
McAfeeGeneric Trojan.gt
Cylanceunsafe
ZillyaExploit.Generic.Win32.171
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052474c1 )
AlibabaBackdoor:Win32/Rescoms.c9b51421
K7GWTrojan ( 0052474c1 )
Cybereasonmalicious.e2d612
ArcabitIL:Trojan.MSILMamut.DAB1
BitDefenderThetaGen:NN.ZemsilF.36680.um0@amy0Yvc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.MJE
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Exploit.Win32.Generic
BitDefenderIL:Trojan.MSILMamut.2737
NANO-AntivirusExploit.Win32.BypassUAC.eximeg
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13bfd35d
EmsisoftIL:Trojan.MSILMamut.2737 (B)
F-SecureTrojan.TR/AD.Remcos.cnzbd
DrWebTrojan.Click3.12113
VIPREIL:Trojan.MSILMamut.2737
TrendMicroTROJ_FRS.0NA103C320
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
JiangminExploit.Generic.wc
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/AD.Remcos.cnzbd
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Apt33
Kingsoftmalware.kb.c.999
MicrosoftBackdoor:Win32/Rescoms.B
ViRobotTrojan.Win32.Z.Agent.342016.EQ
ZoneAlarmHEUR:Exploit.Win32.Generic
GDataIL:Trojan.MSILMamut.2737
VaristW32/Trojan.VIJB-9093
AhnLab-V3Trojan/Win32.Agent.C3141863
VBA32TScope.Trojan.MSIL
ALYacBackdoor.Remcos.A
MalwarebytesMalware.AI.3381331540
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103C320
RisingExploit.Generic!8.3E1 (TFE:C:sR9CKow14sH)
YandexTrojan.Kryptik!4Fnn6uJuwQA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1670890.susgen
FortinetGenerik.JOUCGNM!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3381331540?

Malware.AI.3381331540 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment