Malware

Malware.AI.3505332007 removal guide

Malware Removal

The Malware.AI.3505332007 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3505332007 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Malware.AI.3505332007?


File Info:

name: B91C1E0117AC2619548B.mlw
path: /opt/CAPEv2/storage/binaries/a5ea625fae088c420e54c56898b882ae4a9840bde267a271c1eb3d0d45e760b5
crc32: 1E4135CB
md5: b91c1e0117ac2619548b3fe695d6b215
sha1: 01de8e4d3a71e841c91158f42b01049e0b0c388f
sha256: a5ea625fae088c420e54c56898b882ae4a9840bde267a271c1eb3d0d45e760b5
sha512: 357712d6544bbafd77d721046900c0f84659db73faae68684b28170504116f9bb6f0434e0a94e48c622fcf32ab452174c194a106a66c29c3189a2d989c98db14
ssdeep: 12288:BHIF4+iQisqECgliDnqk79nKpXC/KfUT5EatXk/laDkE+6tjqQ+jVDa/ZS1:BHIFv3LnCPqRpXE2MK+UcDvXsa/ZS1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14015DF08BB1542D3E44EA235EA6DDB69E55ABA3DEA55C2BF310075A33C637C0E443F24
sha3_384: 094344fe9263297e181cd138b9df49238b2e3f6cd0271bc9c628ce5b55b53a8d15ef6919914122153a74d4bac2377949
ep_bytes: cb0b9bfd9b621f7a9e8316eb1cc97e51
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.3505332007 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.93251
FireEyeGeneric.mg.b91c1e0117ac2619
CAT-QuickHealTrojan.Skeeyah.J1
McAfeePacked-FJB!B91C1E0117AC
MalwarebytesMalware.AI.3505332007
ZillyaTrojan.Generic.Win32.360483
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005393141 )
K7GWTrojan ( 005376b01 )
Cybereasonmalicious.117ac2
ArcabitTrojan.Symmi.D16C43
CyrenW32/Zusy.EM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIRH
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.93251
NANO-AntivirusTrojan.Win32.Kryptik.gsuatr
SUPERAntiSpywareTrojan.Agent/Gen-Razy
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Kryptik!1.B34D (C64:YzY0Outo2JF4oRnI)
Ad-AwareGen:Variant.Symmi.93251
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Symmi.93251 (B)
ComodoTrojWare.Win32.Kryptik.TLS@812zm8
DrWebTrojan.DownLoader32.42873
McAfee-GW-EditionBehavesLike.Win32.Autorun.cc
SophosML/PE-A + Mal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ckytw
AviraHEUR/AGEN.1141086
Antiy-AVLTrojan/Generic.ASBOL.C549
MicrosoftVirTool:Win32/CeeInject.AKZ!bit
GDataGen:Variant.Symmi.93251
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Packed.R357404
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34114.2CW@am2hnHh
MAXmalware (ai score=84)
VBA32Trojan.Glupteba
TencentTrojan.Win32.Kryptik.gifya
YandexTrojan.GenAsa!0xM7zILK7cg
IkarusTrojan.Win32.Tiggre
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Malware.AI.3505332007?

Malware.AI.3505332007 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment