Malware

What is “Malware.AI.3545709754”?

Malware Removal

The Malware.AI.3545709754 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3545709754 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • CAPE detected the Nitol malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Malware.AI.3545709754?


File Info:

name: 64C7A2323E3605A9CA48.mlw
path: /opt/CAPEv2/storage/binaries/86116c7010cd432982c36b2cfa292d02dec8e4c93c262ad4ae92b997bee7d258
crc32: 4CDCE905
md5: 64c7a2323e3605a9ca48640c39f952d8
sha1: 7565d3f829ce9161ee25f7e835bdbf7a7d026b1f
sha256: 86116c7010cd432982c36b2cfa292d02dec8e4c93c262ad4ae92b997bee7d258
sha512: 3f44d5480be01d11c67cefca610180de394a34937e5c7f4d2f026bf37607662c5f690381a4d573335e2237d1ececf5ad2b0102caed2f901d23463e871b53c527
ssdeep: 24576:CZGe9L5dVMi86oSLFPb+BBkP9ulgihpSHoFN6WtljaEyJM:CECl0uDL96WOhpSHoFN6WtljaEyJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC55E0D77B375A08D694653134245B5B27613FBE0A31019D31FDBE0A0ABBEE06A3AD0D
sha3_384: 5bf9836a5c2f68c2d1f08a67dfb767cb4fc31e4faa5a767bd6f3c1701ff49ed1a403fc33096c0c34feba2f15b2b2d272
ep_bytes: 6801a35e00680ea35e00c3b724e90800
timestamp: 2020-12-23 17:01:53

Version Info:

0: [No Data]

Malware.AI.3545709754 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.64c7a2323e3605a9
McAfeeBackDoor-EXZ
MalwarebytesMalware.AI.3545709754
K7AntiVirusTrojan ( 0052c8a31 )
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.829ce9
BitDefenderThetaGen:NN.ZexaF.34638.uv0@a4xG51di
VirITTrojan.Win32.Agent.BWB
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.NoobyProtect.G suspicious
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
APEXMalicious
SophosMal/Generic-S
ComodoBackdoor.Win32.Zegost.~BA@4k703s
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
AviraHEUR/AGEN.1200060
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32BScope.Trojan.Bingoml
CylanceUnsafe
RisingTrojan.Generic@AI.99 (RDMK:cmRtazqmK29NLYbtsTQEkhJFsr0P)
SentinelOneStatic AI – Malicious PE
FortinetW32/Filecoder.FV!tr.ransom
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.3545709754?

Malware.AI.3545709754 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment