Malware

What is “Malware.AI.3401590754”?

Malware Removal

The Malware.AI.3401590754 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3401590754 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3401590754?


File Info:

name: 760A665481979FCB04D2.mlw
path: /opt/CAPEv2/storage/binaries/e544d959e3851d9ab529628acb02582d55349361ac5a7a392ebee425f11f1e79
crc32: 99FBCFB9
md5: 760a665481979fcb04d28352fc18f8b7
sha1: d3d7e19b9944817ba38d6d0a9191f15a70bf1a13
sha256: e544d959e3851d9ab529628acb02582d55349361ac5a7a392ebee425f11f1e79
sha512: aa6c151ab11588349c73fdc89920563609631efdf20b28320a37a64ed53bb353456be7fc187aaf5732b73ade8bddd58491b6b063e1ea3bb24a11e653302f13bc
ssdeep: 12288:YsbEghwQQuW+yNaqUZLbooLYi6THT+SKvfL:YsboyWVMLLbooLfWzbI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4D4E0C3E3390DC9D4A50E72D0B3D5E167E2DE2339268A811A3075998B736BB2C7F146
sha3_384: 92484668f97f6c1dac2ae3afd6e0fd4ce51fc9ae6ce4da08041b6a96991f73aba0c4129731a2a5cde0fcf266d6d212ad
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2023-02-27 07:35:14

Version Info:

Comments:
CompanyName: TubeMate Software
FileDescription: TubeMate Player
FileVersion: 5, 5, 1, 0
InternalName: TubeMate Player
LegalCopyright: (C) TubeMate Software. All rights reserved.
LegalTrademarks:
OriginalFilename: TubeMatePlayer.EXE
PrivateBuild:
ProductName: Windows TubeMate
ProductVersion: 5, 5, 1, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.3401590754 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.66492141
ClamAVWin.Malware.Generic-9951960-0
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.66492141
Cylanceunsafe
VIPRETrojan.GenericKD.66492141
SangforTrojan.Win32.Agent.Vy4r
SymantecML.Attribute.HighConfidence
ZonerTrojan.Win32.133812
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.66492141
EmsisoftTrojan.GenericKD.66492141 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.760a665481979fcb
SophosGeneric ML PUA (PUA)
GDataTrojan.GenericKD.66492141
Antiy-AVLTrojan/Win32.PossibleThreat
ArcabitTrojan.Generic.D3F696ED
GoogleDetected
McAfeeRDN/Generic.dx
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.3401590754
TrendMicro-HouseCallTROJ_GEN.R002H06CT23
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.206791192.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.36164.LmuaaGg@geoi
DeepInstinctMALICIOUS

How to remove Malware.AI.3401590754?

Malware.AI.3401590754 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment