Malware

Malware.AI.3559538578 removal tips

Malware Removal

The Malware.AI.3559538578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3559538578 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.3559538578?


File Info:

name: 972DD25B629D21358137.mlw
path: /opt/CAPEv2/storage/binaries/a6cfb3756171c02259cf5ff0a77bb4e36b0720df8fa5ded26b6bfe0b0e72c18f
crc32: 86CDE3F1
md5: 972dd25b629d213581374c4f49467646
sha1: dc9c85779c84b0fcc4a19fa5f4495e07684416ad
sha256: a6cfb3756171c02259cf5ff0a77bb4e36b0720df8fa5ded26b6bfe0b0e72c18f
sha512: 46a387726bcb82b21210871e50113c95f4a52558297c2f66040ee1b1e21745e6ee0589c27877a71f2a6e9c56b72d378ecc1cdcbf1f08158a9f9581103be34e0e
ssdeep: 3072:jqf3JWpOO0FX85Fn3ESTsJ/Jb2cDqCAcyUXLgn6dxzQCuUdLs+C5/qY:jpO/NCwnbFqJUbgnw5yRq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E7345B293B8C9101F7E5477750ABA0B08FBBA5D0F873C7AF600C5599AF5B3A149AC316
sha3_384: 40dafbdb65333e35f4ad31005c73d4b83c2dd918a62c13c703b32d71454c64a9b18243ca6622e23100b0a4000461b651
ep_bytes: ff2500c041003000000000091ffc6005
timestamp: 2046-11-25 03:23:29

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Updater
FileVersion: 1.0.0.0
InternalName: 3.0.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: 3.0.exe
ProductName: Updater
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3559538578 also known as:

LionicTrojan.Win32.Heracles.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.972dd25b629d2135
McAfeeRDN/Generic.rp
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
AlibabaPacked:MSIL/VMProtect.0b25f11b
K7GWTrojan ( 7000001c1 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.VMProtect.A suspicious
APEXMalicious
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGen:Variant.MSILHeracles.22102
MicroWorld-eScanGen:Variant.MSILHeracles.22102
AvastFileRepMalware
Ad-AwareGen:Variant.MSILHeracles.22102
SophosMal/Generic-R + Mal/VMProtBad-A
TrendMicroTROJ_GEN.R002C0RJL21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftGen:Variant.MSILHeracles.22102 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILHeracles.22102
MAXmalware (ai score=86)
ArcabitTrojan.MSILHeracles.D5656
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.C4553580
BitDefenderThetaGen:NN.ZemsilF.34062.ou0@aatgafb
ALYacGen:Variant.MSILHeracles.22102
MalwarebytesMalware.AI.3559538578
TrendMicro-HouseCallTROJ_GEN.R002C0RJL21
YandexRiskware.VMProtect!e+/IcoszXpQ
IkarusTrojan.MSIL.Vmprotect
MaxSecureTrojan.Malware.82199810.susgen
FortinetRiskware/Application
AVGFileRepMalware
Cybereasonmalicious.b629d2

How to remove Malware.AI.3559538578?

Malware.AI.3559538578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment