Malware

About “Malware.AI.3570483189” infection

Malware Removal

The Malware.AI.3570483189 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3570483189 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3570483189?


File Info:

name: 2737C84FC93B8EE65906.mlw
path: /opt/CAPEv2/storage/binaries/9274de79bceb396b9b927b0cd187a27fe391a1a5df5ec4dd6d4128a7cebd5423
crc32: CDC9D090
md5: 2737c84fc93b8ee65906ced5875ee25f
sha1: da1068b03d74a394132614577719daeeb06831e0
sha256: 9274de79bceb396b9b927b0cd187a27fe391a1a5df5ec4dd6d4128a7cebd5423
sha512: 518c7e9a6e81cb2f0be050ad6134e6c720308ee3842c8c13ee9658f2b55778f87a2df00cb9f7c1403b486c3f901d0f24df93566fb1ffb045690be8b907463331
ssdeep: 1536:2AwWU+hDA5bTxzoO49xgAGuwa2+rk/EfIrhoRP:eWzhM5bTxzc9xg2waAJhoJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BA38F13D4A2C87EE8792EFA2F3550F5D52B6CAC9C4F782721E81D4CD5952AA13EC312
sha3_384: 175d1d5e1097ade999aff7b8dfc67f25fc9090ee1136feccbb8d8e24867cf420d7b6ddf30152a91d741239a2ad1741fd
ep_bytes: 558becb90d0000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Kingsoft Corporation
FileDescription: 金山毒霸进程管理器绿色版by刘金
FileVersion: 2011,10,19,1666
InternalName: kprocmgrex
LegalCopyright: Copyright (C) 1998-2011 Kingsoft Corporation
OriginalFilename: kprocmgrex.exe
ProductName: Kingsoft Internet Security
ProductVersion: 9,0,46411,1666
Translation: 0x0000 0x04b0

Malware.AI.3570483189 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
SkyhighBehavesLike.Win32.BadFile.nh
McAfeeArtemis!2737C84FC93B
Cylanceunsafe
ZillyaTrojan.Keylogger.Win32.36075
SangforTrojan.Win32.Agent.Vwop
BitDefenderThetaGen:NN.ZelphiF.36802.gG2@a4uyYRmb
APEXMalicious
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b6cd97
F-SecureHeuristic.HEUR/AGEN.1350350
Trapminemalicious.high.ml.score
GoogleDetected
AviraHEUR/AGEN.1350350
VaristW32/ABRisk.YKLM-6459
Kingsoftmalware.kb.a.861
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
MalwarebytesMalware.AI.3570483189
RisingTrojan.Generic@AI.100 (RDMK:359b0TgnyQBa7wSg2BCouw)
YandexTrojanSpy.KeyLogger!otqOFfcRFTI
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.3570483189?

Malware.AI.3570483189 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment