Malware

Malware.AI.3426664738 (file analysis)

Malware Removal

The Malware.AI.3426664738 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3426664738 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.3426664738?


File Info:

name: C417467A71603BF9373D.mlw
path: /opt/CAPEv2/storage/binaries/99e670906e0585ff8b380ed79e5c4a299ca46dc7d121f79513c9710c89925a64
crc32: 7846FA78
md5: c417467a71603bf9373d85720947aa53
sha1: 14d819592c4c5a287f8237fbae8afb136a58404d
sha256: 99e670906e0585ff8b380ed79e5c4a299ca46dc7d121f79513c9710c89925a64
sha512: ae768d8473121ca4ecaa2593dc4425b3ddf7ff712f34749c69dbd3fef1e8dc74207df2e0647a8e430dc7662e8c7a96f4e39abcf88de83d9fb4c402734c47e1e1
ssdeep: 3072:yT62kltl7utrZ8KIw4T3k69nhTaRGAQyeFo:yTwzlP3kwnBAfQVF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1F3E322F6050C15C1F139F4046288DA9A698F552C57E7E7F0BAB216CAF1397FD0A46F
sha3_384: d348df8c93efe0178600c6240e27eab724137611780d81ac6397d8444144f198021af83bece08b8bf2b56fbbcb8755a9
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-25 04:11:46

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Leon Miller
FileDescription: Vkk
FileVersion: 1.0.0.0
InternalName: Vkk.exe
LegalCopyright: Copyright © 2021
LegalTrademarks: Leon Miller
OriginalFilename: Vkk.exe
ProductName: Vkk
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3426664738 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.HydraPOS.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.95618
FireEyeGeneric.mg.c417467a71603bf9
ALYacGen:Variant.Lazy.95618
CylanceUnsafe
SangforTrojan.Win32.Agent.V71s
BitDefenderGen:Variant.Lazy.95618
Cybereasonmalicious.92c4c5
CyrenW32/ABRisk.RUUV-4929
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.HydraPOS.gen
AlibabaTrojan:MSIL/HydraPOS.2addbe1e
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:uqUIiy0CJNqt0W+ZGm+Z/Q)
Ad-AwareGen:Variant.Lazy.95618
EmsisoftGen:Variant.Lazy.95618 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.moderate.ml.score
SophosGeneric PUA BE (PUA)
AviraHEUR/AGEN.1216789
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Lazy.95618
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5182107
McAfeeRDN/Real Protect-LS
MalwarebytesMalware.AI.3426664738
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H07FP22
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34742.km0@aaL8ug
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.3426664738?

Malware.AI.3426664738 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment