Malware

Malware.AI.3527126388 removal instruction

Malware Removal

The Malware.AI.3527126388 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3527126388 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Windows Defender AV emulator via files
  • Harvests cookies for information gathering

How to determine Malware.AI.3527126388?


File Info:

name: C115953EBF851E6C80A0.mlw
path: /opt/CAPEv2/storage/binaries/1bf35504f954e7ed0de88fde70c8355cc70e44b43e40c28c82cdc4c0af8e823d
crc32: B5B5C47A
md5: c115953ebf851e6c80a0912788e40cb6
sha1: 7d1e08aa6331f7e09f7b45e3f720a6ec13a1dfab
sha256: 1bf35504f954e7ed0de88fde70c8355cc70e44b43e40c28c82cdc4c0af8e823d
sha512: 026c8aa3e3365a1cb174091d3f6729a5612efadaeead60d9adaaea759ad9732536c9f97bcf014cfa7800dd557bbc01bb8753452c64a3eb0dd9270475d5333076
ssdeep: 49152:luiO3MIlZ2EpGaOy/107BH9xG/R7uA2XjNirp36wnYydgvFYFFqe:luiOMcoyK7LxIR7uA2xSnYydgvF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AEE59E22BB088132ED7601B1995D6B2F584CAA34077804D7F3DC4A6D2BE46D36B37B5B
sha3_384: 70a19a26af15986c8fd99a46f4bd5a4beb7c7e17fb809f3374d7e657f343fba402b8c5cba0c824220d02609113aec963
ep_bytes: e8d20e0000e98efeffff558bec6a00ff
timestamp: 2018-03-11 20:19:17

Version Info:

0: [No Data]

Malware.AI.3527126388 also known as:

LionicTrojan.Win32.Reconyc.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Sigma.1
FireEyeGeneric.mg.c115953ebf851e6c
CAT-QuickHealTrojan.Sigmal.S2281364
ALYacTrojan.Ransom.Sigma
MalwarebytesMalware.AI.3527126388
K7AntiVirusTrojan ( 0052a2251 )
AlibabaTrojan:Win32/Reconyc.cf99264c
K7GWTrojan ( 0052a2251 )
Cybereasonmalicious.ebf851
VirITTrojan.Win32.Encoder.BKZT
CyrenW32/Sigma.A.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Ransom.Sigma.1
Ad-AwareGen:Variant.Ransom.Sigma.1
SophosMal/Generic-S
ComodoMalware@#3519kdhs7jrge
BitDefenderThetaGen:NN.ZexaF.34742.!EX@a4Ltrmii
ZillyaTrojan.Reconyc.Win32.21542
TrendMicroTROJ_FRS.0NA103JN18
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Ransom.Sigma.1 (B)
AviraTR/FileCoder.yrncr
KingsoftWin32.Troj.Undef.(kcloud)
GDataGen:Variant.Ransom.Sigma.1
AhnLab-V3Trojan/Win32.FileCoder.C2437657
VBA32BScope.Trojan.Reconyc
MAXmalware (ai score=96)
TrendMicro-HouseCallTROJ_FRS.0NA103JN18
TencentMalware.Win32.Gencirc.114cdea4
TACHYONRansom/W32.Sigma.3112960
FortinetW32/Filecoder_Sigma.A!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3527126388?

Malware.AI.3527126388 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment