Malware

Malware.AI.3606323894 (file analysis)

Malware Removal

The Malware.AI.3606323894 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3606323894 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3606323894?


File Info:

name: AF7B2368F0D30218E89B.mlw
path: /opt/CAPEv2/storage/binaries/ac487aa8863b8ada55c64dcd22d1016814b09fbc1dbdbabfa81a6821741fa68b
crc32: 4613F46F
md5: af7b2368f0d30218e89b9a0e939d9560
sha1: 12408918d2326b991d360ec4f8bbbdfa757a108a
sha256: ac487aa8863b8ada55c64dcd22d1016814b09fbc1dbdbabfa81a6821741fa68b
sha512: fe0c4598b2ab11ffc0bc72001257f129952fd8c01df2c44ef2a44d17dff4db28f95e8f098178f9ea85cecc879443d54b0218ad4eab495dcc986e1d7fc993bc10
ssdeep: 49152:at2Nh0N7lSdutUYzfPHnwNI0gJg/8kNjrk:U2IJlSYtTPHwNIi/8kB4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197A533EBE9C1DD7FE10FA5319447DA6942B0DF103A622AA39F544F1FCB161229C4AE43
sha3_384: 132bea85d720354207e0b1224bf0d7ed31a8b7a11f80c26c84a7a04e9da8f14fa68322f0676209bdd66d9af16db27f85
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Malware.AI.3606323894 also known as:

BkavW32.AIDetect.malware2
LionicRiskware.MSIL.PCOptimizer.1!c
Elasticmalicious (high confidence)
CAT-QuickHealRisktool.NSIS.Pcoptimizer.A
McAfeeArtemis!AF7B2368F0D3
CylanceUnsafe
ZillyaDownloader.Generic.Win32.4696
SangforPUP.Win32.MyPCBackup.8
K7AntiVirusAdware ( 004bd8f61 )
K7GWAdware ( 004bd8f61 )
CyrenW32/Trojan.GHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/MyPCBackup.D potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.MSIL.PCOptimizer.b
NANO-AntivirusRiskware.Win32.MyPCBackup.edkmak
AvastWin32:Malware-gen
EmsisoftApplication.PCBackOpt (A)
ComodoApplicUnwnt@#17whqqhjnj6rk
DrWebProgram.Unwanted.1152
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosGeneric PUA BC (PUA)
AviraHEUR/AGEN.1220205
Antiy-AVLTrojan/Generic.ASMalwNS.6EAF
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ViRobotAdware.Mypcbackup.2151413
ZoneAlarmnot-a-virus:RiskTool.MSIL.PCOptimizer.b
MicrosoftTrojan:Win32/Occamy.CAC
AhnLab-V3PUP/Win32.BundleInstaller.R194324
MAXmalware (ai score=100)
VBA32CIL.HeapOverride.Heur
MalwarebytesMalware.AI.3606323894
TrendMicro-HouseCallTROJ_GEN.R002H0CL421
YandexRiskware.PCOptimizer!jw8yt8Fju4U
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/PCOptimizer
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Malware.AI.3606323894?

Malware.AI.3606323894 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment