Malware

Malware.AI.3545686836 information

Malware Removal

The Malware.AI.3545686836 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3545686836 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.3545686836?


File Info:

name: F20A549C7B5142E16385.mlw
path: /opt/CAPEv2/storage/binaries/bed550b6a0384ea0296433d2da6d0e2313ebd74e2eb69f767d185eaf2b49a35c
crc32: 11F48D67
md5: f20a549c7b5142e16385cf2a650def8a
sha1: 073db5f00b61136cd03382044e27efc7a6d2f0de
sha256: bed550b6a0384ea0296433d2da6d0e2313ebd74e2eb69f767d185eaf2b49a35c
sha512: ab9ffab72a7d3b2a5f0e5cd3d4f498ed0784adc9691d5f11b3a80134789bd8fd06d97ee010d6ce513b63c433c35247418229d694a89553a1e7b0fc05588b9f81
ssdeep: 1536:lHVJEbODDClaKJnaiTeImiI/mXxl7a9BEEqPb4NbZRndhMEs504T32:nJEbKClahUxFa3qPboPrMEsq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121F32933B9E86556C6424DB00D3AF6B83F2E7C2F11039E073554FE4D2E75412BA6A72A
sha3_384: 36c6ea1a9dcec12138f48c0a49d1adf07e87556913fc5119e347c3f9b440959bbacb622f9add28f29133fa549ad3f43c
ep_bytes: 68701d4000e8f0ffffff000040000000
timestamp: 2014-12-06 20:39:24

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Microsoft
ProductName: WinRar
FileVersion: 1.00
ProductVersion: 1.00
InternalName: test
OriginalFilename: test.exe

Malware.AI.3545686836 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanGen:Variant.Bulz.865909
FireEyeGeneric.mg.f20a549c7b5142e1
CAT-QuickHealTrojan.Agent
McAfeeRDN/Generic.hbg
CylanceUnsafe
K7AntiVirusP2PWorm ( 004b1f481 )
AlibabaTrojan:Win32/Generic.e84f25be
K7GWP2PWorm ( 004b1f481 )
Cybereasonmalicious.c7b514
CyrenW32/Backdoor.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/VB.RSJ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Acxxgjdk-9843394-0
KasperskyTrojan.Win32.Agent.alodk
BitDefenderGen:Variant.Bulz.865909
NANO-AntivirusTrojan.Win32.KeyLogger.djyzac
Ad-AwareGen:Variant.Bulz.865909
EmsisoftGen:Variant.Bulz.865909 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R007C0PKM21
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.cm
SophosMal/Generic-S
Paloaltogeneric.ml
GDataGen:Variant.Bulz.865909
MaxSecureTrojan.Malware.300983.susgen
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C693285
BitDefenderThetaAI:Packer.9B0C94FD20
ALYacGen:Variant.Bulz.865909
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.3545686836
TrendMicro-HouseCallTROJ_GEN.R007C0PKM21
eGambitTrojan.Generic
FortinetW32/VB.RSJ!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Malware.AI.3545686836?

Malware.AI.3545686836 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment