Malware

Malware.AI.3499560565 removal guide

Malware Removal

The Malware.AI.3499560565 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3499560565 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3499560565?


File Info:

name: 86F1509901029DB5C824.mlw
path: /opt/CAPEv2/storage/binaries/456b399653fddb19e178e4e0626eb099e952138cea77d02e347bf8b0ea063af8
crc32: DE5DEFDC
md5: 86f1509901029db5c824ec11240a13fd
sha1: 49068da02a690e1956f2c827fd6e3f2b7008e5ab
sha256: 456b399653fddb19e178e4e0626eb099e952138cea77d02e347bf8b0ea063af8
sha512: 40d211aa73169fbe25329f2c6c756ad7179f70d3314d4ab5f8130ca3711dee542875a55c0b269bee748e4b1af11645aba0e1de247b35eb55bf9d6c835dd80460
ssdeep: 6144:K9JB5iVEMWoGsplPbE83Vjv4llwN8llwNBI:8B8VEM02A83VD4llwN8llwN6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149A49E2334818636C058213578A1E99047F4AD3359A3DF233F953EFDBAB65925F0EA63
sha3_384: e701b2a139fec6ba570da5db6c2a94556493943f30bac13e2e134cc42bf6fb6547704ccda25741b76e01e78a140c211d
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-02-21 01:01:41

Version Info:

Translation: 0x0000 0x04b0
Comments: Hangi meslek size uygun hemen öğrenin.
CompanyName: Fatih Rehberlik Servisi
FileDescription: Meslek Testi
FileVersion: 1.1.0.0
InternalName: Meslek Testi.exe
LegalCopyright: Copyright © Fatih Rehberlik Servisi
OriginalFilename: Meslek Testi.exe
ProductName: MeslekTesti
ProductVersion: 1.1.0.0
Assembly Version: 1.1.0.0

Malware.AI.3499560565 also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.30365792
FireEyeGeneric.mg.86f1509901029db5
ALYacTrojan.GenericKD.30365792
K7AntiVirusTrojan ( 005272da1 )
AlibabaTrojan:MSIL/Generic.135574b6
K7GWTrojan ( 005272da1 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/MSIL_Agent.DX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.SKC
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.30365792
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Ednt
Ad-AwareTrojan.GenericKD.30365792
EmsisoftTrojan.GenericKD.30365792 (B)
TrendMicroTROJ_GEN.R002C0PKS21
McAfee-GW-EditionGenericRXDH-CR!86F150990102
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
GDataTrojan.GenericKD.30365792
AviraHEUR/AGEN.1127746
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.BTSGeneric
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D1CF5860
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Tiggre.R234314
McAfeeGenericRXDH-CR!86F150990102
MalwarebytesMalware.AI.3499560565
TrendMicro-HouseCallTROJ_GEN.R002C0PKS21
YandexTrojan.Agent!KRxO29MN5fE
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.SKC!tr
BitDefenderThetaGen:NN.ZemsilF.34062.Bq1@ai8T5If
AVGWin32:Malware-gen
Cybereasonmalicious.901029
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3499560565?

Malware.AI.3499560565 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment