Malware

Malware.AI.3396481666 removal

Malware Removal

The Malware.AI.3396481666 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3396481666 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Creates a hidden or system file
  • Detects Bochs through the presence of a registry key
  • Harvests cookies for information gathering

Related domains:

example.org
ipv4only.arpa
populardiesel.info
wpad.local-net

How to determine Malware.AI.3396481666?


File Info:

name: F8D915BED78A6057B8F6.mlw
path: /opt/CAPEv2/storage/binaries/cbb9f8519ef1926d6f98951f418de3f953f44899c9df78ed830f93b38588823a
crc32: FA829ABC
md5: f8d915bed78a6057b8f6585db21a72ce
sha1: 4a0ffb8683ae67abca7e2ce82f2fc8ffd22054be
sha256: cbb9f8519ef1926d6f98951f418de3f953f44899c9df78ed830f93b38588823a
sha512: 16158706c67ec839cb819b88bcb8262fc28b4788b2d77ca1115b7be1750248e765e9d2c0efcfb6d33b6f6b72a58f006dd6018db86b6f73f4e5d675221e2b809a
ssdeep: 49152:BaFgbJM93xA81eZKSt9II8Pxm0p3ZSLYmlFHYQTRgVc34hsqcc:GgtyWExm0p3dmlFgVNCqc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC067C327689543FD0BB0B36483BA764593FBF653A12C94F67F4090C8E766816D2A34B
sha3_384: aa4871873f5eb77dd6933357b32c3f112b863eb7715228dd4b258afd1907f54f48069f53e755b1862eb6dc5db6d53791
ep_bytes: eb1466623a432b2b484f4f4b90e9aca0
timestamp: 2017-12-20 13:38:21

Version Info:

FileDescription: Consumo_CPFL_Energia_
FileVersion: 1.0.0.0
ProgramID: com.embarcadero.Consumo_CPFL_Energia_
ProductName: Consumo_CPFL_Energia_
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Malware.AI.3396481666 also known as:

LionicTrojan.Win32.Generic.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38098767
FireEyeGeneric.mg.f8d915bed78a6057
McAfeeGenericRXDP-BE!F8D915BED78A
K7AntiVirusTrojan-Downloader ( 005190801 )
AlibabaTrojanDownloader:Win32/Generic.361be033
K7GWTrojan-Downloader ( 005190801 )
BitDefenderThetaGen:NN.ZexaF.34294.SN0@a4XKZXki
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.CFB
TrendMicro-HouseCallTROJ_GEN.R002C0DKN21
AvastWin32:Dropper-gen [Drp]
KasperskyUDS:Trojan-Downloader.Win32.Generic
BitDefenderTrojan.GenericKD.38098767
NANO-AntivirusTrojan.Win32.Razy.ewnkzo
Ad-AwareTrojan.GenericKD.38098767
EmsisoftTrojan.GenericKD.38098767 (B)
TrendMicroTROJ_GEN.R002C0DKN21
McAfee-GW-EditionGenericRXDP-BE!F8D915BED78A
SophosMal/Generic-S
Paloaltogeneric.ml
GDataTrojan.GenericKD.38098767
JiangminTrojanDownloader.Generic.betu
AviraHEUR/AGEN.1130797
Antiy-AVLTrojan/Generic.ASMalwS.237A62C
GridinsoftRansom.Win32.Skeeyah.sa
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 99)
AhnLab-V3Malware/Gen.Generic.C2309680
VBA32Trojan.Skeeyah
ALYacTrojan.GenericKD.38098767
MAXmalware (ai score=83)
MalwarebytesMalware.AI.3396481666
APEXMalicious
RisingTrojan.Generic@ML.96 (RDML:pyTpArYXV+1eapFiB88cVg)
YandexTrojan.GenAsa!Ww0GFCWPSt0
FortinetW32/Delf.CFB!tr.dldr
AVGWin32:Dropper-gen [Drp]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.3396481666?

Malware.AI.3396481666 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment