Malware

Malware.AI.3548298971 removal

Malware Removal

The Malware.AI.3548298971 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3548298971 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • CAPE detected the Emotet malware family
  • Attempts to modify proxy settings

How to determine Malware.AI.3548298971?


File Info:

name: EB3A252BB685113CC92B.mlw
path: /opt/CAPEv2/storage/binaries/045ef86160e0a77a2a6d766cacbca7801b9e861d75644cdd71795f09282af4fd
crc32: FE8BE193
md5: eb3a252bb685113cc92b291b81987fd4
sha1: da3dff5adcd74128eff18b973037534d93ded659
sha256: 045ef86160e0a77a2a6d766cacbca7801b9e861d75644cdd71795f09282af4fd
sha512: e455a1a6109b9cc8a6913ed73e5e4cedb546dbb44e3e42b27cc43369e17c22513e819919f6ab1db06da9f1b8aa5079e0e14305657437c4674780e5bd86905b5c
ssdeep: 6144:iPK8AZ4u8owxyx4yGJGxMnOocRPkT0MnYc9U/cHxo:iy8AZ4u40xrIGx1oYMTbJUcK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180648C12B7A08776D6A30E324DED8B7DE2BDB91C8E31C74763909E0EEC71651493631A
sha3_384: fbaf4ac811cc3d56caacfca7f5f368072baeda5536ff03411541a6154713c6dd73d5dd5042ff0bf3ffb890267ad675db
ep_bytes: 558bec6aff68683f430068cc5a410064
timestamp: 2020-07-20 12:16:16

Version Info:

CompanyName:
FileDescription: LineCounter MFC Application
FileVersion: 1, 0, 0, 1
InternalName: LineCounter
LegalCopyright: Copyright (C) 2001
LegalTrademarks:
OriginalFilename: LineCounter.EXE
ProductName: LineCounter Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Malware.AI.3548298971 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Emotet.L!c
MicroWorld-eScanTrojan.GenericKDZ.68847
ClamAVWin.Packed.Emotet-9778865-0
McAfeeEmotet-FRI!EB3A252BB685
CylanceUnsafe
ZillyaBackdoor.Emotet.Win32.396
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0056e08f1 )
AlibabaTrojan:Win32/Emotet.c0674660
K7GWTrojan ( 0056e08f1 )
Cybereasonmalicious.bb6851
VirITTrojan.Win32.Emotet.BLZ
CyrenW32/Kryptik.BQM.gen!Eldorado
SymantecTrojan.Emotet
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HFAA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
BitDefenderTrojan.GenericKDZ.68847
NANO-AntivirusTrojan.Win32.Emotet.hofjwq
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.10bb4553
Ad-AwareTrojan.GenericKDZ.68847
EmsisoftTrojan.Emotet (A)
DrWebTrojan.Emotet.987
VIPRETrojan.GenericKDZ.68847
TrendMicroTrojanSpy.Win32.EMOTET.SMTHK
McAfee-GW-EditionEmotet-FRI!EB3A252BB685
FireEyeGeneric.mg.eb3a252bb685113c
SophosMal/Generic-R + Troj/Agent-BFFL
IkarusTrojan-Banker.Emotet
GDataTrojan.GenericKDZ.68847
JiangminBackdoor.Emotet.nf
AviraTR/AD.Emotet.CN
Antiy-AVLTrojan/Generic.ASMalwS.3F43
KingsoftWin32.Troj.Banker.(kcloud)
ArcabitTrojan.Generic.D10CEF
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C4164696
Acronissuspicious
VBA32Trojan.Wacatac
ALYacTrojan.Agent.Emotet
MAXmalware (ai score=84)
MalwarebytesMalware.AI.3548298971
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMTHK
RisingTrojan.Kryptik!1.C89F (CLASSIC)
YandexTrojan.Kryptik!bRKU4pZ0FDg
MaxSecureTrojan.Malware.11417434.susgen
FortinetW32/GenericKDZ.6889!tr
BitDefenderThetaGen:NN.ZexaF.34754.tq0@a0jSDedk
AVGWin32:BankerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3548298971?

Malware.AI.3548298971 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment