Malware

Malware.AI.3561114578 removal

Malware Removal

The Malware.AI.3561114578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3561114578 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3561114578?


File Info:

name: 03789401D0FE1A10B99D.mlw
path: /opt/CAPEv2/storage/binaries/598ef017df1016d4e3d7085ecde3e32affbd5da40e8ca0d2c5a783e03b008968
crc32: 84DCDF06
md5: 03789401d0fe1a10b99df85f1b9e5e67
sha1: f0077b9ea477b90d7046d7e37b8627c39d6f7b42
sha256: 598ef017df1016d4e3d7085ecde3e32affbd5da40e8ca0d2c5a783e03b008968
sha512: 041e137bf64a7ac73ba2ab51a7c5ee34ff56c65b13cce7682961004958b7ed49bead5887a06975915da73a4fa2a44f6cbcf9eddf7cd78927c47e86a46b646f4d
ssdeep: 24576:8e4WY+9ehxRtgggHtHIPqRQVYeyd8jKyUkA8rvD+IKKSHFCfu+xL+5jmClgJ9Y7:8ep9ehvtgD1IPqmKK7UkA8rvD+IKKSHF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D055D0A1B4448CFDF46A2072D45BC9540496BE6A86A110DF76EEBF4874B3B82117FF0E
sha3_384: 9ec5bbfd6e76a0f383be921705b293e70812c490e8d08af49a5d0f0de535e40e363035855bc372c5e28cd0ad90319240
ep_bytes: e8db650000e989feffff8bff558bec5d
timestamp: 2003-01-05 12:26:41

Version Info:

Comments:
CompanyName: Foxit Corporation
FileDescription: Foxit Reader 5.0, Best Reader for Everyday Use!
FileVersion: 5, 0, 2, 0718
InternalName: Foxit Reader.exe
LegalCopyright: Copyright (C) 2009-2011 Foxit Corporation
LegalTrademarks:
OriginalFilename: Foxit Reader.EXE
PrivateBuild:
ProductName: Foxit Reader
ProductVersion: 5, 0, 2, 0718
SpecialBuild:
Translation: 0x0804 0x04b0

Malware.AI.3561114578 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35535472
ClamAVWin.Malware.Bskd-9753126-0
FireEyeGeneric.mg.03789401d0fe1a10
CAT-QuickHealTrojan.Salgorea.S1558393
ALYacTrojan.GenericKD.35535472
MalwarebytesMalware.AI.3561114578
VIPRETrojan.GenericKD.35535472
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 004aeef51 )
AlibabaTrojan:Win32/Salgorea.379
K7GWTrojan ( 004aeef51 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36250.sr0@a8JogBli
VirITTrojan.Win32.Generic.YCQ
CyrenW32/A-7f827d17!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDropper.Agent.QUM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.35535472
NANO-AntivirusTrojan.Win32.TrjGen.djsyov
SUPERAntiSpywareHeur.Agent/Gen-FakeFoxit
AvastWin32:Agent-AYZG [Cryp]
TencentMalware.Win32.Gencirc.10bb7cab
EmsisoftTrojan.GenericKD.35535472 (B)
F-SecureHeuristic.HEUR/AGEN.1312668
DrWebTrojan.Siggen6.25279
ZillyaDropper.Agent.Win32.174770
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosTroj/Trickbo-WO
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.SXNB19
JiangminTrojan/Generic.azstc
AviraHEUR/AGEN.1312668
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Agent.QGO@57p1tw
ArcabitTrojan.Generic.D21E3A70
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Salgorea.C!MTB
GoogleDetected
AhnLab-V3Trojan/Win.HDC.R423272
Acronissuspicious
McAfeeGenericRXCZ-WT!03789401D0FE
MAXmalware (ai score=84)
VBA32Trojan.Salgorea
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.DR.Agent!w3b8OCIQNkM
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.AYZG!tr
AVGWin32:Agent-AYZG [Cryp]
Cybereasonmalicious.1d0fe1
DeepInstinctMALICIOUS

How to remove Malware.AI.3561114578?

Malware.AI.3561114578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment