Malware

Malware.AI.3468206902 removal instruction

Malware Removal

The Malware.AI.3468206902 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3468206902 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.3468206902?


File Info:

name: B1E67AEFAB6D7617F367.mlw
path: /opt/CAPEv2/storage/binaries/fe38a94dbcc534dca15c02396edd5a21b232dbd9aeab6c0b4ad327db8e24ccd9
crc32: B5A25F17
md5: b1e67aefab6d7617f3678fbaf30b45f1
sha1: 17801f837096441d58d396737439e41964e536be
sha256: fe38a94dbcc534dca15c02396edd5a21b232dbd9aeab6c0b4ad327db8e24ccd9
sha512: 53652a7b7b7d3b3e37566d2ada48fe0036aaf2d8d3821a98f124124e8884b8abcf296d66b36bef70494afc969f06bfe2cf0bb2c81a322f0e1646d9d35d1593eb
ssdeep: 3072:qc/h2rHHxzyRVdsmjhsde/MCUbpsmPD6out5JN:qc8dO3dsmtLjUFL+oS5f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D248C52A6004898F76D0B315A46FAE408999E3C64E4F58FF57CBE3B6C720974AB314F
sha3_384: 9d6ff29dc9876c4085583a28a71ec993b3a9fedcd2897ca700d97b06d07688b762611dd2126eb7dfa799433431be7a20
ep_bytes: 60be003047008dbe00e0f8ff5789e58d
timestamp: 2013-11-06 07:06:22

Version Info:

0: [No Data]

Malware.AI.3468206902 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.mBMX
MicroWorld-eScanGen:Trojan.Heur.mmW@!pIdtmcO
ClamAVWin.Packed.Urelas-9779774-0
FireEyeGeneric.mg.b1e67aefab6d7617
ALYacGen:Trojan.Heur.mmW@!pIdtmcO
MalwarebytesMalware.AI.3468206902
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0048c72d1 )
AlibabaTrojanSpy:Win32/CardSpy.1464c15e
K7GWSpyware ( 0048c72d1 )
Cybereasonmalicious.fab6d7
ArcabitTrojan.Heur.EF09C5
BitDefenderThetaAI:Packer.D25E00041C
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Spy.CardSpy.NAF
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.mmW@!pIdtmcO
NANO-AntivirusTrojan.Win32.CardSpy.cqwefm
AvastWin32:Malware-gen
TencentWin32.Trojan.Spy.Bgow
EmsisoftGen:Trojan.Heur.mmW@!pIdtmcO (B)
F-SecureTrojan.TR/Spy.Cardspy.jggly
VIPREGen:Trojan.Heur.mmW@!pIdtmcO
McAfee-GW-EditionBehavesLike.Win32.Generic.dt
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Cardspy.jggly
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Tgenic
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win.Z.Cardspy.210432.P
GDataGen:Trojan.Heur.mmW@!pIdtmcO
GoogleDetected
AhnLab-V3Backdoor/Win.Plite.R487157
McAfeeArtemis!B1E67AEFAB6D
VBA32Trojan.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CF223
RisingTrojan.Dorv!8.422 (CLOUD)
IkarusTrojan.Win32.Gupboot
FortinetW32/ULPM.2C75!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3468206902?

Malware.AI.3468206902 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment