Malware

Malware.AI.3589999488 removal guide

Malware Removal

The Malware.AI.3589999488 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3589999488 virus can do?

  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3589999488?


File Info:

name: C9A0B2008615FD7DFBF4.mlw
path: /opt/CAPEv2/storage/binaries/241a4ac07f04e1392c2b194ad0d1140dd526f2071740eba0b48811bea0f64d0f
crc32: 19B430D1
md5: c9a0b2008615fd7dfbf4677a086bda8a
sha1: 5432478485a6dd9cc33727d0bbecc11c0e466646
sha256: 241a4ac07f04e1392c2b194ad0d1140dd526f2071740eba0b48811bea0f64d0f
sha512: 614ad1f23cca79c3d7333ba39d35b516d5847741982e4013c26068d30a3b43a2c74d3a6d29e7aa66a3a902d2d532e6bf6cce7de8fc379348e53eca2fb461e19a
ssdeep: 6144:KDy+bnr+kp0yN90QEWxDl9ZLkWh7ZNcPR5sUYYxRUIz5sfqdZ/SIzS7QHzb:NMr0y90oRZybpdhI0zb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED74F113A7DC4073EDB517B098F603830B3ABC615D3983AF2745989A0CB26D5A83577B
sha3_384: ed61c0e09b101192923d9aa4014f15ef0c605b9eb774885fe7e891a983069ba0ce4df5ccd4333307366c7e4bf2532a77
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0409 0x04b0

Malware.AI.3589999488 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanGen:Heur.Crifi.1
FireEyeGen:Heur.Crifi.1
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Heur.Crifi.1
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3607616
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00536d121 )
AlibabaTrojanDownloader:Win32/Deyma.db996c08
K7GWTrojan ( 005690671 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Genus.RPR
CyrenW32/Kryptik.JKR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Malware.Doina-10001799-0
KasperskyUDS:Trojan.MSIL.Agent.gen
BitDefenderGen:Heur.Crifi.1
NANO-AntivirusTrojan.Win32.Disabler.jvbcxo
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Backdoor.Agent.Gtgl
EmsisoftGen:Heur.Crifi.1 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Siggen19.32857
VIPREGen:Heur.Crifi.1
TrendMicroTROJ_FRS.0NA103HN23
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosTroj/PlugX-EC
IkarusTrojan.Spy.Stealer
GDataWin32.Trojan.PSE.12PH8GL
JiangminBackdoor.Mokes.hou
GoogleDetected
AviraTR/AD.Nekark.sgdjp
Antiy-AVLTrojan/Win32.SmokeLoader
ArcabitTrojan.Crifi.1
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:MSIL/plugx!atmn
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Mokes.R593092
Acronissuspicious
McAfeeArtemis!C9A0B2008615
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3589999488
PandaTrj/Chgt.AD
RisingBackdoor.Mokes!8.619 (TFE:4:7n4IsIjnBDK)
YandexTrojan.Disabler!G6z7qDxyklM
SentinelOneStatic AI – Malicious SFX
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.3589999488?

Malware.AI.3589999488 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment