Malware

Should I remove “Malware.AI.3442744122”?

Malware Removal

The Malware.AI.3442744122 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3442744122 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3442744122?


File Info:

name: A3162A734601CBD23076.mlw
path: /opt/CAPEv2/storage/binaries/11e5fcb713a4ff76a67d6e6159998710851f78e15a5e871df89d783cbe354905
crc32: 74C3D831
md5: a3162a734601cbd23076a9ccf2968639
sha1: 8911a252911a43de2f961b62638bcc1d3cd2dee2
sha256: 11e5fcb713a4ff76a67d6e6159998710851f78e15a5e871df89d783cbe354905
sha512: d83e2b6f88d3fdca2ff9be10224a7305dd5cdc86395e3d37bdc8d223d4258f1a24346ab29803895e5f3760f9ced934c015e425bdcda7e6a03f03c4a65e6b58cd
ssdeep: 49152:wIqYNwA/veJNXnlpsacsjJFMdVrJ+T6wWu0fGXRcywXYDYW9z:wRJisjLMbrM2wWu00QS9z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185C5011261FECC63D3E10872F5E9DBF0A928BD23FA61859BD2803DD97973D839522641
sha3_384: 57c72c3f5d212db7e2a1f0817e5a77b18d90317caa20cc6a2684622b69e21120bba989231370597938d7cc37d6f1bba5
ep_bytes: e8c6040000e978feffffcccccccccccc
timestamp: 2023-08-01 09:26:10

Version Info:

0: [No Data]

Malware.AI.3442744122 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zenpak.tsrS
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68890460
McAfeeArtemis!A3162A734601
MalwarebytesMalware.AI.3442744122
SangforTrojan.Win32.Save.a
ArcabitTrojan.Generic.D41B2F5C
CyrenW32/ABRisk.YMIN-0082
APEXMalicious
BitDefenderTrojan.GenericKD.68890460
AvastWin32:Evo-gen [Trj]
SophosMal/Generic-S
VIPRETrojan.GenericKD.68890460
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.a3162a734601cbd2
EmsisoftTrojan.GenericKD.68890460 (B)
GoogleDetected
ViRobotTrojan.Win.Z.Agent.2663935
GDataTrojan.GenericKD.68890460
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Uztuby.R594987
ALYacTrojan.GenericKD.68890460
MAXmalware (ai score=82)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09HS23
MaxSecureTrojan.Malware.216151588.susgen
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.3442744122?

Malware.AI.3442744122 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment