Malware

Malware.AI.3593860676 removal tips

Malware Removal

The Malware.AI.3593860676 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3593860676 virus can do?

  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3593860676?


File Info:

name: DEF416DC4849EB247BD9.mlw
path: /opt/CAPEv2/storage/binaries/5af0b9e08724451944daca9368671a0d5f6ca02730cf6cdc29ad644370f51cd8
crc32: BAD18B59
md5: def416dc4849eb247bd92daa34393379
sha1: 51af6f1b98847a7c41ced80bbdf6f37649a3c048
sha256: 5af0b9e08724451944daca9368671a0d5f6ca02730cf6cdc29ad644370f51cd8
sha512: 65157fc21f4ba5f6300494020684f3c5ed550dd48801f4fb327b74342998abb37af18ba9fcef93dce8834240700dbe7107a4d001f73e309d9cb043a5531c07d3
ssdeep: 393216:E71fXHQlqcw7aqkFcwcozeUp0+Vw2LjYofzQ+9QLUYOEOXi9H:SXp7CLcaw2wog1k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146F6338F573697BDDC1E823B7A2DB27C20CBAF9F25C917368E5239CA383289454512D1
sha3_384: ab80c72464743b3d16045dda2fe4634f2b88d55e0a28eff001f39fe8ed385adf4a1803b5e4dffe05d44a93f7078ec365
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2020-08-19 01:11:03

Version Info:

FileVersion: 1.5.0.0
FileDescription: EasyRC - 一键重装
ProductName: EasyRC
ProductVersion: 1.5.0.0
CompanyName: EasyRC
LegalCopyright: (C) 2018-2020 FirPE Team All Rights Reserved.
Comments: EasyRC - 一键重装
Translation: 0x0804 0x04b0

Malware.AI.3593860676 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.li0G
Elasticmalicious (high confidence)
FireEyeGeneric.mg.def416dc4849eb24
SkyhighBehavesLike.Win32.Generic.wc
MalwarebytesMalware.AI.3593860676
ZillyaTrojan.Kryptik.Win32.4326811
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0042f7bb1 )
AlibabaTrojan:Win32/Kryptik.7b8543bc
K7GWTrojan ( 0042f7bb1 )
Cybereasonmalicious.b98847
BitDefenderThetaGen:NN.ZexaF.36792.@puaaKFJ4Aeb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
AvastWin32:Trojan-gen
SophosMal/Generic-S
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Suspicious PE
GoogleDetected
Antiy-AVLTrojan/Win32.Masson
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
VaristW32/Kryptik.GSV.gen!Eldorado
McAfeeArtemis!DEF416DC4849
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H01GA23
RisingTrojan.Kryptik!8.8 (TFE:5:EWPwdBJxi6G)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GWEK!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3593860676?

Malware.AI.3593860676 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment