Malware

How to remove “Malware.AI.3473804976”?

Malware Removal

The Malware.AI.3473804976 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3473804976 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Harvests cookies for information gathering

How to determine Malware.AI.3473804976?


File Info:

name: 2F10F5206EFFF67FA7F3.mlw
path: /opt/CAPEv2/storage/binaries/d8884912854923e55fa0b850e3370389aeccff171f7c3207bb1d60a98cf6f767
crc32: CE1929E5
md5: 2f10f5206efff67fa7f3223031adc630
sha1: 87e3bafd8490336f3b1409577952373064b5f150
sha256: d8884912854923e55fa0b850e3370389aeccff171f7c3207bb1d60a98cf6f767
sha512: 67f37906907b07b847ad0eb34460fb66235d5f0563df2a010db34ad05fe3d9c952e92558047aa9d8d6f4a2a27c760b617b92a830d024ec1753f342ecc3fc8527
ssdeep: 6144:NlJ4Nwo7lOpT2hkWGzxU7p05YsC+saEcq:F5o8T6kWc27jd+saEcq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114648D137AC280B2F1764A3459E1EE7C493C39641F5D990EA7944BBE0A33E5C5237BA3
sha3_384: 02b7ed5ef6bcf79fd62394d755dc668072ded49bcaf43eb3a0a75ee26326a994db8dc1fab6f6eb137ff77e44697a9f70
ep_bytes: e8f7040000e98efeffff3b0da8d04200
timestamp: 2017-05-23 11:58:52

Version Info:

0: [No Data]

Malware.AI.3473804976 also known as:

LionicTrojan.Win32.Snojan.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.12531381
FireEyeTrojan.GenericKD.12531381
ALYacTrojan.GenericKD.12531381
CylanceUnsafe
SangforTrojan.VBS.Agent.PIS
K7AntiVirusTrojan-Downloader ( 0051adcb1 )
AlibabaTrojanDownloader:VBS/Snojan.42ed0808
K7GWTrojan-Downloader ( 0051adcb1 )
Cybereasonmalicious.06efff
SymantecTrojan.VBdrop
ESET-NOD32VBS/TrojanDownloader.Agent.PIS
Paloaltogeneric.ml
ClamAVWin.Dropper.Snojan-6611652-0
BitDefenderTrojan.GenericKD.12531381
NANO-AntivirusTrojan.Win32.Mlw.eusoyj
APEXMalicious
Ad-AwareTrojan.GenericKD.12531381
EmsisoftTrojan.GenericKD.12531381 (B)
F-SecureMalware.JS/Dldr.Agent.eiapx
McAfee-GW-EditionBehavesLike.Win32.AdwareLinkury.fh
SophosMal/Generic-S (PUA)
IkarusTrojan-Downloader.VBS.Agent
AviraJS/Dldr.Agent.eiapx
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataTrojan.GenericKD.12531381
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Snojan.C2241666
Acronissuspicious
McAfeeArtemis!2F10F5206EFF
MAXmalware (ai score=100)
VBA32Trojan.Script
MalwarebytesMalware.AI.3473804976
AvastScript:SNH-gen [Trj]
TencentWin32.Trojan.Snojan.Hryu
MaxSecureTrojan.Malware.300983.susgen
FortinetVBS/Agent.303D!tr.dldr
AVGScript:SNH-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.3473804976?

Malware.AI.3473804976 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment