Malware

About “Malware.AI.3491794472” infection

Malware Removal

The Malware.AI.3491794472 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3491794472 virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Kannada
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3491794472?


File Info:

name: 3C48E994B9ED83F737E1.mlw
path: /opt/CAPEv2/storage/binaries/5aab39f9e38c60cd61f3ef96136fb641d70f5c284e55bd4a1eefeb3c9045f5a7
crc32: 5C4F6A3D
md5: 3c48e994b9ed83f737e1b8ad3374beab
sha1: ccfe0d038f9b03dcbea5f859306e3cb582da1d9f
sha256: 5aab39f9e38c60cd61f3ef96136fb641d70f5c284e55bd4a1eefeb3c9045f5a7
sha512: 2dc0f715f0c3d46580dccd8ec190ac419fdaf2f7b4c880671cb54afcc2a535bfe29a6a3053138c431c4052920baa2c94ee8dfb87ada4a294050cc18426fbba50
ssdeep: 98304:8+USaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxSaxV:PUSeSeSeSeSeSeSeSeSeSeSeSeSeSeSg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C46ADEC2240D4BAC6A4FBF3EE7F8FCA6D686DC58554822F142A7D4F3DA22D01D52245
sha3_384: 2f884ea0bce40d3c724650747446f8bef363344428c3ece5d9ee7463008667cfb545d05742d6f6e3c0e06a2970142dd9
ep_bytes: e8cb530000e989feffffc70110134000
timestamp: 2021-11-20 10:11:26

Version Info:

FileVersions: 17.26.2.32
Copyrighz: Copyright (C) 2022, pozkarte
ProjectVersion: 2.82.22.61

Malware.AI.3491794472 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.SpyBot.1126
MicroWorld-eScanTrojan.GenericKDZ.88965
FireEyeGeneric.mg.3c48e994b9ed83f7
CAT-QuickHealRansom.Stop.P5
ALYacTrojan.GenericKDZ.88965
VIPRETrojan.GenericKDZ.88965
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005948191 )
K7GWTrojan ( 005948191 )
Cybereasonmalicious.38f9b0
CyrenW32/Kryptik.GSB.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HPWK
ClamAVWin.Malware.Azorult-9949206-0
BitDefenderTrojan.GenericKDZ.88965
TencentTrojan-Downloader.Win32.Deyma.ya
Ad-AwareTrojan.GenericKDZ.88965
SophosML/PE-A + Mal/Agent-AWV
ZillyaTrojan.Kryptik.Win32.3806642
McAfee-GW-EditionBehavesLike.Win32.Lockbit.th
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.88965 (B)
IkarusTrojan.Win32.Crypt
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.50E8
MicrosoftTrojan:Win32/Raccoon.RB!MTB
GDataWin32.Trojan.PSE.2CNFW4
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GDD.R500067
Acronissuspicious
McAfeePacked-GDD!3C48E994B9ED
VBA32TrojanPSW.RedLine
MalwarebytesMalware.AI.3491794472
APEXMalicious
RisingStealer.Agent!8.C2 (TFE:5:U4u0FeUox0T)
YandexTrojan.Kryptik!JC2Sb/yjhvg
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SpyBot.1126!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.3491794472?

Malware.AI.3491794472 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment