Malware

Malware.AI.3507973581 malicious file

Malware Removal

The Malware.AI.3507973581 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3507973581 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.3507973581?


File Info:

name: F02F185F40757BE61775.mlw
path: /opt/CAPEv2/storage/binaries/87e7245f144712b8e51cefe8134f703a0c41be77805113954ffdac4d7a853f5f
crc32: F6CFF8A8
md5: f02f185f40757be61775db4c10887f85
sha1: 33aedacd0069104109a28b8d38ac84298d312634
sha256: 87e7245f144712b8e51cefe8134f703a0c41be77805113954ffdac4d7a853f5f
sha512: 94e146a385f1a4949e733e5b07ad8a3487eccd09be6ba261d62dea3137cccfe622b6140d3a72eaaa276b6e3b765e8c547bd229ea1b4c675e82ae77294289222f
ssdeep: 12288:hYV6MorX7qzuC3QHO9FQVHPF51jgcqUIELnSB:2BXu9HGaVHEug
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2E45C8659626645D4AC373C0A217A76CF4A5C7BBE70E12D40E77C8E173BCE680BAC71
sha3_384: 4dd76e62a437a89944f8fc089af53001fb5faf2506e04fed35b9620feec88df2f951fe30731bbcc10452fe0814540018
ep_bytes: 60be00504d008dbe00c0f2ff57eb0b90
timestamp: 2021-04-30 11:04:11

Version Info:

FileVersion: 3.4.7.3
Comments: SolidShare.Net Unattended Installer
FileDescription: SolidShare.Net Unattended Installer
ProductVersion: 3.4.7.3
LegalCopyright: © 2021 By KiNGHaZe
CompanyName: SolidShare TEAM
ProductName: Windows 10 Manager
Translation: 0x0409 0x04b0

Malware.AI.3507973581 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Nymeria.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.4235
FireEyeAIT:Trojan.Nymeria.4235
McAfeeRDN/Generic PUP.z
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusUnwanted-Program ( 005766001 )
K7GWUnwanted-Program ( 005766001 )
Cybereasonmalicious.f40757
ESET-NOD32a variant of Win32/HackTool.Silentall.N potentially unsafe
APEXMalicious
Paloaltogeneric.ml
BitDefenderAIT:Trojan.Nymeria.4235
AvastWin32:Malware-gen
Ad-AwareAIT:Trojan.Nymeria.4235
SophosGeneric PUA DD (PUA)
ZillyaTool.Silentall.Win32.714
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.jh
EmsisoftAIT:Trojan.Nymeria.4235 (B)
GDataWin32.Riskware.Shasoli.A
WebrootPua.Yukleyici
AviraTR/ATRAPS.Gen
MAXmalware (ai score=80)
MicrosoftRansom:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C4384068
ALYacAIT:Trojan.Nymeria.4235
MalwarebytesMalware.AI.3507973581
TrendMicro-HouseCallTROJ_GEN.R002H0CL321
YandexTrojan.Igent.bVVyyz.11
IkarusTrojan.AutoIt.Acapulco
FortinetRiskware/Silentall
AVGWin32:Malware-gen

How to remove Malware.AI.3507973581?

Malware.AI.3507973581 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment