Malware

About “Malware.AI.3415239725” infection

Malware Removal

The Malware.AI.3415239725 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3415239725 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Malware.AI.3415239725?


File Info:

name: D539955D059F16EF8BC0.mlw
path: /opt/CAPEv2/storage/binaries/4e041659645248e4a858d17da5e0bdda9227dd2762dc0c618fd923bc79461c82
crc32: 5CC7DD93
md5: d539955d059f16ef8bc00838581dc678
sha1: 62a17db9c79a540902dc0e8c8d9a3a3ef9cebafc
sha256: 4e041659645248e4a858d17da5e0bdda9227dd2762dc0c618fd923bc79461c82
sha512: 3c510dd5ef5c8ae185346bc26cfdde8a676197fcbc5d1d81cc4ffcf4e505c1a55e4a9fd5779da6e94f1b6ca89775dfb8c046a8327c4fb23fc92f9f8f199511e1
ssdeep: 384:RlFguo6jfzv48odOokQ7MNxQlNd/+uV+RFBYfwMqBNeLNek+vD:HsizxNqN+lFBFMq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BA23834B3584923C4654EFA49639714033AF613051AEE8E3AC92DDF5EA3F60C522F9B
sha3_384: dc1f2497e1ba96c5fb9b37413dcc6ebc274f69ae201ac5149d5eb2bd5d14742f183bae0e0e4369bcc434588e470f8d12
ep_bytes: ff250020400000000000000000000000
timestamp: 2013-02-27 18:47:19

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: MuBMBFPIWDOSZYCMImZA.exe
LegalCopyright:
OriginalFilename: MuBMBFPIWDOSZYCMImZA.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3415239725 also known as:

LionicAdware.MSIL.Midia.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.PCMega.1
McAfeePUP-FBB
CylanceUnsafe
VIPRETrojan.MSIL.Reveton.a (v)
K7AntiVirusTrojan ( 700000121 )
AlibabaAdWare:MSIL/Midia.de52ec91
K7GWTrojan ( 700000121 )
Cybereasonmalicious.d059f1
BitDefenderThetaGen:NN.ZemsilF.34212.bm0@aeJ66si
VirITTrojan.Win32.DownLoader8.UVR
CyrenW32/MSIL_Dloader.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.PCMega.H
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Midia.gen
BitDefenderGen:Variant.Adware.PCMega.1
NANO-AntivirusTrojan.Win32.RiskGen.dcurxx
SUPERAntiSpywareAdware.PCMega
AvastFileRepMalware [PUP]
TencentMsil.Adware.Pcmega.Wpjd
Ad-AwareGen:Variant.Adware.PCMega.1
EmsisoftGen:Variant.Adware.PCMega.1 (B)
ComodoTrojWare.MSIL.TrojanDownloader.Agent.BCG@4veuin
DrWebTrojan.DownLoader8.14083
ZillyaAdware.PCMega.Win32.306
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionPUP-FBB
SentinelOneStatic AI – Suspicious PE
FireEyeGen:Variant.Adware.PCMega.1
SophosGeneric PUA GC (PUA)
APEXMalicious
GDataGen:Variant.Adware.PCMega.1
JiangminTrojan/Foreign.cnb
WebrootW32.Trojan.Gen
AviraADWARE/Adware.Gen2
Antiy-AVLTrojan[Ransom]/Win32.Foreign
KingsoftWin32.Troj.Undef.(kcloud)
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.Midia.gen
MicrosoftBackdoor:Win32/Bladabindi!ml
TACHYONTrojan/W32.DN-Small.21504.AC
AhnLab-V3Win-Trojan/Agent.21504.VQ
VBA32Hoax.Foreign
ALYacGen:Variant.Adware.PCMega.1
MAXmalware (ai score=99)
MalwarebytesMalware.AI.3415239725
IkarusPUA.SoftwareBundler
FortinetAdware/PCMega
AVGFileRepMalware [PUP]
PandaTrj/Dtcontx.B

How to remove Malware.AI.3415239725?

Malware.AI.3415239725 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment