Malware

Should I remove “Malware.AI.3401632609”?

Malware Removal

The Malware.AI.3401632609 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3401632609 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.3401632609?


File Info:

name: 36A5C7E13939A8904EC1.mlw
path: /opt/CAPEv2/storage/binaries/058cec2c1121a02f101af6e17d43d2af6d96ea6aff0d93412eae0a26bf3582b0
crc32: EB493CB5
md5: 36a5c7e13939a8904ec148df2cf5cb2e
sha1: 32277dcbdbda8b929fa64c7a7338f567c1f81e4e
sha256: 058cec2c1121a02f101af6e17d43d2af6d96ea6aff0d93412eae0a26bf3582b0
sha512: edcbf29b3c88e9b40b30db9efc2ca72054575913c4dd066bc523082510d3c6b7441a259f9782306b6716144173573119c25d171d93e101002314f36528b246eb
ssdeep: 12288:QYP3ULbutWuOsxyMh6wK4ahTD6shPO4ceEj2HdJPkJ+HEAXCSoI9vtHEP22AalQu:HPV8tM/K4ahvzO4cZKHHijAXM+G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C21512386FD55928C6E817B7D0B914E0D6B07B95B60F876F206856FD6F832D48E0232B
sha3_384: a4dcbcb9a2306f9f924cccc119fa38c6e965a02bc8b6e89835c34e08acacf68162ed8d1c2ef033444488f3523a07777d
ep_bytes: ff2500a04800006d73636f7265652e64
timestamp: 2052-06-21 04:21:38

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: coolvegas
FileVersion: 1.0.0.0
InternalName: coolvegas.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: coolvegas.exe
ProductName: coolvegas
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3401632609 also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47578666
FireEyeGeneric.mg.36a5c7e13939a890
ALYacTrojan.GenericKD.47578666
CylanceUnsafe
K7AntiVirusTrojan ( 7000001c1 )
AlibabaTrojan:MSIL/VMProtBad.a41410d6
K7GWTrojan ( 7000001c1 )
CrowdStrikewin/malicious_confidence_80% (W)
CyrenW32/MSIL_Kryptik.CRG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/HackTool.Agent.PE
APEXMalicious
BitDefenderTrojan.GenericKD.47578666
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.47578666
SophosML/PE-A + Mal/VMProtBad-A
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.GenericKD.47578666 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47578666
AviraTR/Hacktool.kmmey
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D5FE2A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4774818
McAfeeArtemis!36A5C7E13939
MAXmalware (ai score=84)
MalwarebytesMalware.AI.3401632609
TrendMicro-HouseCallTROJ_GEN.R002H0CL621
IkarusTrojan.MSIL.Vmprotect
FortinetMSIL/Agent.PE!tr
BitDefenderThetaGen:NN.ZemsilF.34062.4u0@a8bgW0g
AVGWin32:Trojan-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3401632609?

Malware.AI.3401632609 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment