Malware

Malware.AI.346887861 removal tips

Malware Removal

The Malware.AI.346887861 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.346887861 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

Related domains:

wpad.local-net

How to determine Malware.AI.346887861?


File Info:

name: 4AA0343D5B3E29FC0915.mlw
path: /opt/CAPEv2/storage/binaries/636c1386362c41159df9eafbfb776874fcadfeb3020ed423e4e4f1313b953609
crc32: BA9894AB
md5: 4aa0343d5b3e29fc09158f3260944b15
sha1: 7d702d2f1d45b2c23889e958516b16f41978e3b0
sha256: 636c1386362c41159df9eafbfb776874fcadfeb3020ed423e4e4f1313b953609
sha512: 54ca8b7892eed88bf80b69f4f1804a69b687019587fd742a1ff0ab844d0b78d103024a4ffc8f71f6871dc550421132ac53ef534cca8d0eae5a0dd0cdbeb98b73
ssdeep: 12288:2PXTrAezvn8AWSl3zDI3gJJCeYx+aWNMg0ZY/1+nnTktwr4eTL3bVk:2PXIA8nSlQ3g87WwZxnnf8ev3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184F4DE95B64B8EE9C88414318DBFCFB46E003DEA9550569237F53F3F7EB9221A811236
sha3_384: 6b9bf330644690031052c8de655537f90c135bc0a76befad38652312b1fe88c5c913e03d1a303fdfdf51293f06c51692
ep_bytes: 60e80000000058059f0200008b3003f0
timestamp: 2021-08-02 09:08:27

Version Info:

Comments:
CompanyName: Jerry Software
FileDescription: Media Player
FileVersion: 7, 11, 6, 0
InternalName: Media Player
LegalCopyright: (C) Jerry Software. All rights reserved.
LegalTrademarks:
OriginalFilename: MediaPlayer.EXE
PrivateBuild:
ProductName: Media Player
ProductVersion: 7, 11, 6, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.346887861 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeRDN/Generic.grp
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1508311
SangforTrojan.Win32.Generic.ky
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Generic.67ececae
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.EKYV-0461
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
SophosGeneric PUA HN (PUA)
TrendMicroTROJ_GEN.R002C0PH821
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bc
FireEyeGeneric.mg.4aa0343d5b3e29fc
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.haalh
WebrootW32.Trojan.Gen
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R449177
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.346887861
TrendMicro-HouseCallTROJ_GEN.R002C0PH821
TencentWin32.Trojan.Generic.Pfjk
eGambitUnsafe.AI_Score_68%
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34294.Vm0@aW!mz1ci
AVGWin32:Malware-gen
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.7164915.susgen

How to remove Malware.AI.346887861?

Malware.AI.346887861 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment