Malware

How to remove “Malware.AI.3578961403”?

Malware Removal

The Malware.AI.3578961403 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3578961403 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (10 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to create or modify system certificates

Related domains:

ocsp.digicert.com
www.trisunsoft.com
www.duplicatefilefinder4pc.com
duplicatefilefinder4pc.com
www.bing.com
s7.addthis.com
www.google-analytics.com
embed.tawk.to
ocsp.pki.goog
ocsp.omniroot.com
g.symcd.com

How to determine Malware.AI.3578961403?


File Info:

crc32: 6E292587
md5: 8d282dae469c287ff5c66f53e1d68ed7
name: 8D282DAE469C287FF5C66F53E1D68ED7.mlw
sha1: 617d458fe2434492737be317a921efe752ee0c53
sha256: 5be5e4b0abb9189c524560b999e9449817ff9220e4d7e853656f82b392349e0b
sha512: 31fa194b9c724d4ed5d4b06da3c35d6a29d39f16bdb8818df91ebb2de2ea78abc9b491f65e592def5adb5ec2068e87d43d7b937b4fc4951f5bb08629e999d9a6
ssdeep: 12288:5ExGg+U1dB+uImwwZGgeJmA2v/IOBp7rh9:5OGg+sK8VA2v/xBX9
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2004-2021 TriSun Software Limited. All rights reserved.
Assembly Version: 16.0.79.0
InternalName: Duplicate File Finder Plus.exe
FileVersion: 16.0.079
CompanyName: TriSun Software Limited
LegalTrademarks:
Comments: Duplicate File Finder Plus
ProductName: Duplicate File Finder Plus
ProductVersion: 16.0.079
FileDescription: Duplicate File Finder Plus
OriginalFilename: Duplicate File Finder Plus.exe

Malware.AI.3578961403 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0054f7ba1 )
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWTrojan ( 0054f7ba1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Hesv.gen
TrendMicroTROJ_GEN.R005C0DFC21
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.8d282dae469c287f
AviraHEUR/AGEN.1132183
Antiy-AVLTrojan/Generic.ASMalwS.2B576C3
MicrosoftTrojan:Win32/Nanocore.AC!MTB
McAfeeArtemis!8D282DAE469C
MalwarebytesMalware.AI.3578961403
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0DFC21
FortinetW32/Hesv!tr
AVGFileRepMalware

How to remove Malware.AI.3578961403?

Malware.AI.3578961403 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment