Malware

How to remove “Malware.AI.3545801043”?

Malware Removal

The Malware.AI.3545801043 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3545801043 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3545801043?


File Info:

name: F1A332A542BF978B68AD.mlw
path: /opt/CAPEv2/storage/binaries/4ff65ff820cad2cc224552d9291aa6c12c89f91170ac5aef83a8bade857da0ce
crc32: 38CF9A60
md5: f1a332a542bf978b68ad6b85bc5b3181
sha1: 86ceae0cf671869ec1bf3f0cd4139f91cded33e7
sha256: 4ff65ff820cad2cc224552d9291aa6c12c89f91170ac5aef83a8bade857da0ce
sha512: f5cbf174d4852190829c31c307039ad3ed351c3de2b3d503bf9e13a571628b1cb456a64550c541077e31abad5b3f8c83adb49f87598287e5a0bcf9a2451fc6b9
ssdeep: 3072:L8HMuxjPubqcBzXAYXoL7hLux1DwAOgCeHMmkhlYauRb8NnBBAvK2D5Z3hVe9zPd:MLSsxhLfeHehlWA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C934E751FA0CAD94E4A976F38826811123B25E29D375D60E39BE35194BF33C3EC66E0D
sha3_384: f7955951ea0bf028078292998227dbc6ffb7637a841e4340b22240cc67429bd7f6fb898076049db31b8b360d711d3245
ep_bytes: ff250020400000000000000000000000
timestamp: 2011-02-13 19:32:09

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Hijack This
FileDescription: Hijack This
FileVersion: 1.0.0.0
InternalName: Saddam`s Crypter.exe
LegalCopyright: Copyright ©Hijack inc
OriginalFilename: Saddam`s Crypter.exe
ProductName: Hijack This
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3545801043 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.440725
FireEyeGen:Variant.Ursu.440725
McAfeeGenericRXBI-VE!F1A332A542BF
CylanceUnsafe
ZillyaTool.Crypter.Win32.2271
K7AntiVirusHacktool ( 004df4091 )
AlibabaTrojan:MSIL/Generic.0e6a5a25
K7GWHacktool ( 004df4091 )
Cybereasonmalicious.542bf9
BitDefenderThetaGen:NN.ZemsilCO.34182.pq0@aidK3ho
CyrenW32/MSIL_Troj.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/HackTool.Crypter.AW
TrendMicro-HouseCallTROJ_GEN.R002C0PB422
AvastWin32:Trojan-gen
BitDefenderGen:Variant.Ursu.440725
NANO-AntivirusTrojan.Win32.Crypter.gdwhpk
TencentWin32.Trojan.Ursu.Ecjr
EmsisoftRiskware.Crypter (A)
ComodoMalware@#18dw85d7g774s
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PB422
McAfee-GW-EditionGenericRXBI-VE!F1A332A542BF
SophosMal/Generic-S
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Ursu.440725
ALYacGen:Variant.Ursu.440725
MAXmalware (ai score=99)
MalwarebytesMalware.AI.3545801043
APEXMalicious
YandexRiskware.Crypter!tGnV6+RSZ8Y
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Crypter.AW!tr
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen

How to remove Malware.AI.3545801043?

Malware.AI.3545801043 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment