Malware

Malware.AI.3411098601 removal

Malware Removal

The Malware.AI.3411098601 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3411098601 virus can do?

  • A file was accessed within the Public folder.
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3411098601?


File Info:

name: 847665D074CF1E49F943.mlw
path: /opt/CAPEv2/storage/binaries/b94ab521737914356c987eeffe37ba116fb7fd341804bfdd50ad015bb9dae7b0
crc32: 3636EEBA
md5: 847665d074cf1e49f943924087d014ee
sha1: 06a72df9cb973abb1e10be355d7f971b7e5a6f94
sha256: b94ab521737914356c987eeffe37ba116fb7fd341804bfdd50ad015bb9dae7b0
sha512: ec35555e10353537d82999e3b34fd7124e11dbbbafa6e91821641ea403ce62c69a9fbb2c903702fed7fc7467a01fb598a06dae883e17c60e26d3878e15ac3827
ssdeep: 12288:4inDufG1y0p/6TnzdFZA1kykfJsKaiFQNEJWdVH7:TD6GYi/6TzdFZAm3JdaT6g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BFD49F23F3924837D1731B745C1B62A9693ABF101E28A5463BEC1D8C5F3A6A13D293D7
sha3_384: 4e01034ad51acafc9085696fdfadff6ffeb5ae0490afcabb7fe7e550aac313688acd44ef2c162713712614f582691482
ep_bytes: 558bec83c4f0b8d8404800e88812f8ff
timestamp: 2012-04-19 15:30:08

Version Info:

0: [No Data]

Malware.AI.3411098601 also known as:

BkavW32.Common.1FFC57BD
SkyhighBehavesLike.Win32.Gnamer.jh
MalwarebytesMalware.AI.3411098601
ZillyaDropper.Dorifel.Win32.17359
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.9cb973
BitDefenderThetaGen:NN.ZelphiCO.36792.MKW@aKvE56jj
CynetMalicious (score: 100)
APEXMalicious
SophosGeneric Reputation PUA (PUA)
Trapminemalicious.high.ml.score
Antiy-AVLTrojan/Win32.Zpevdo
Kingsoftmalware.kb.a.952
VBA32BScope.Adware.Presenoker
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06JC23
RisingTrojan.Generic@AI.95 (RDML:1R/8K+ZFIAH9YkAyxPxDEg)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.3411098601?

Malware.AI.3411098601 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment