Malware

Malware.AI.3552599394 malicious file

Malware Removal

The Malware.AI.3552599394 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3552599394 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Malware.AI.3552599394?


File Info:

name: F508582C86E67098F394.mlw
path: /opt/CAPEv2/storage/binaries/9af0fb559afa0c8929a1483a0e6c98d740c9b337fbf7d13295207922b825f0a5
crc32: 9EF0A81B
md5: f508582c86e67098f394611c6111d098
sha1: 0944e353a9c07bfc91aa680d23bc78c759ff96cf
sha256: 9af0fb559afa0c8929a1483a0e6c98d740c9b337fbf7d13295207922b825f0a5
sha512: 130c2f252820cc4414ff92446a699ffeec48fac65b9daf2e70fec6a79d6f58aaf47e2c4cb45c7cfb180264e30c729ee81c0783c5a37c114eb34b5f46b11707b2
ssdeep: 1536:Qh8Zc0c2TXH53F/y8fnFZTd6Ue6IWVvmfYC+zyl+U8/6OI:U8Zc0hTH53F/y0nzTd6UjIWVvn+ow
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102D3B06355A672CEF8B29F3E82D61D02CB4AB245436F846D15C2110F0904BD66E9FFA5
sha3_384: 7416b3a957107aec5e8c760d522fe66f8f70589337a60f1b7075c4ad645c0051ae80a7c6ceb10bac512d67b494a310c1
ep_bytes: 558bec83ec24893424687c4940008914
timestamp: 2006-08-18 14:35:13

Version Info:

CompanyName: Macromedia, Inc.
FileDescription: Macromedia Flash Player 7.0 r19
FileVersion: 7,0,19,0
InternalName: Macromedia Flash Player 7.0
LegalCopyright: Copyright © 1996-2003 Macromedia, Inc.
LegalTrademarks: Macromedia Flash Player
OriginalFilename: SAFlashPlayer.exe
ProductName: Shockwave Flash
ProductVersion: 7,0,19,0
Translation: 0x0409 0x04b0

Malware.AI.3552599394 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BPRR
CAT-QuickHealTrojan.Quolko.A
ALYacTrojan.Agent.BPRR
CylanceUnsafe
VIPRETrojan.Agent.BPRR
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0047bf9a1 )
K7GWTrojan ( 0047bf9a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Virus.Virut.gen
VirITTrojan.Win32.Cryptic.EBU
CyrenW32/Ramnit.H.gen!Eldorado
SymantecPacked.Protexor!gen1
tehtrisGeneric.Malware
ESET-NOD32Win32/Virut.NBP
APEXMalicious
ClamAVWin.Packed.Ramnit-9946126-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BPRR
NANO-AntivirusTrojan.Win32.Rmnet.ddidny
SUPERAntiSpywareTrojan.Agent/Gen-ShieldFace
AvastWin32:MalOb-FE [Cryp]
TencentTrojan.Win32.Ramnit.a
Ad-AwareTrojan.Agent.BPRR
ComodoTrojWare.Win32.Spy.Zbot.WEBA@4min4f
DrWebTrojan.Rmnet.1
ZillyaTrojan.Lebag.Win32.229
TrendMicroTROJ_RAMNIT.SMD
McAfee-GW-EditionBehavesLike.Win32.Infected.cz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f508582c86e67098
SophosML/PE-A + W32/Ramnit-BM
IkarusVirus.Win32.Heur
GDataTrojan.Agent.BPRR
JiangminWin32/Virut.bv
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.A6E
ViRobotWorm.Win32.A.Net-Koobface.197632
MicrosoftTrojan:Win32/Bitrep.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Krap.R27995
McAfeePWS-Zbot.gen.di
VBA32Malware-Cryptor.Win32.General.4
MalwarebytesMalware.AI.3552599394
TrendMicro-HouseCallTROJ_RAMNIT.SMD
RisingWorm.Win32.Koobface.ji (CLASSIC)
YandexTrojan.GenAsa!bqvDTpij54g
SentinelOneStatic AI – Malicious PE
FortinetW32/KRYPTIK.FH!tr
BitDefenderThetaGen:NN.ZexaF.34806.iu0@aSBV8niG
AVGWin32:MalOb-FE [Cryp]
PandaTrj/Pck_Pretorx.A

How to remove Malware.AI.3552599394?

Malware.AI.3552599394 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment