Malware

Should I remove “Malware.AI.3481384615”?

Malware Removal

The Malware.AI.3481384615 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3481384615 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Malware.AI.3481384615?


File Info:

name: FC02B011D98984EFFD83.mlw
path: /opt/CAPEv2/storage/binaries/aa4a319fca123580778834d1bb0998243d0e2e16bcefd3889155dee27feec38a
crc32: 3CE6406C
md5: fc02b011d98984effd837bee9e4f760b
sha1: 60be66bd3671799e69251df7d35ffd4b08f4a13e
sha256: aa4a319fca123580778834d1bb0998243d0e2e16bcefd3889155dee27feec38a
sha512: 35fa853af760ec2b031b6ab45ad7ef830e0b96febdc06a1a6b480cbe2191c218240a32e858c1f06e0d8d2c1cf55f4ca7dc273834dfcdbfe0719b751de3f1e624
ssdeep: 3072:C36RnYNMOXelmnBCsuz0eU0Vdria9hsfz70s5jrLsTfGGt+zeQdvfFelJNQL83pX:C3BNtXnBgz0elHvu46z9RdwNZpNx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195049CA2D513B4CDF206037D7D00C75259959CA6A2D1A7D478B02F8C83A683F9E6BF1E
sha3_384: 8d392e4ba9312051d69a058ebedd2c0b00815640df694c6b6201c7d23bc180f389b8632db87d4d4cdc253922714e4562
ep_bytes: 6a40680010000068a08601006a00ff15
timestamp: 2012-09-05 20:26:28

Version Info:

0: [No Data]

Malware.AI.3481384615 also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.AutoRun.o!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fc02b011d98984ef
CAT-QuickHealWorm.AutoRun
McAfeeGenericRXLG-IK!FC02B011D989
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0052ca6a1 )
AlibabaWorm:Win32/AutoRun.a1b5d3b4
K7GWEmailWorm ( 0052ca6a1 )
Cybereasonmalicious.1d9898
CyrenW32/Kryptik.AJG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.Agent.AFG
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Worm.Win32.AutoRun.pef
BitDefenderGen:Variant.Downloader.126
MicroWorld-eScanGen:Variant.Downloader.126
TencentWin32.Worm.Autorun.Ectm
Ad-AwareGen:Variant.Downloader.126
SophosML/PE-A + Troj/Agent-BCGS
ComodoEmailWorm.Win32.AutoRun.KA@719dtc
DrWebWin32.HLLW.Autoruner3.499
TrendMicroTROJ_GEN.R002C0PL321
EmsisoftGen:Variant.Downloader.126 (B)
Paloaltogeneric.ml
GDataWin32.Trojan.PSE.T0QFSA
JiangminTrojan.Generic.fwsid
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASBOL.C6BE
MicrosoftPWS:Win32/Zbot!ml
AhnLab-V3Malware/Win32.RL_Generic.R295338
Acronissuspicious
BitDefenderThetaAI:Packer.10D9AA541E
ALYacGen:Variant.Downloader.126
MAXmalware (ai score=81)
VBA32BScope.Worm.Autorun
MalwarebytesMalware.AI.3481384615
TrendMicro-HouseCallTROJ_GEN.R002C0PL321
RisingWorm.Autorun!1.AFBF (CLASSIC)
YandexWorm.AutoRun!YMivqm0By4k
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.AFG!tr
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3481384615?

Malware.AI.3481384615 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment