Malware

How to remove “Malware.AI.3609987981”?

Malware Removal

The Malware.AI.3609987981 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3609987981 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3609987981?


File Info:

name: FF24F75B7BB6C4262898.mlw
path: /opt/CAPEv2/storage/binaries/99fbd4828a30a80af2a421ce053772b4fb237961a7fb598d0a90c9b8a6e4d771
crc32: ABAAB017
md5: ff24f75b7bb6c42628987e7335a01c1a
sha1: 6a196db3c3079f6e8a748418faeeb6de1a99f44a
sha256: 99fbd4828a30a80af2a421ce053772b4fb237961a7fb598d0a90c9b8a6e4d771
sha512: b3ed697669aef6a946f7dff2173268adc15684246f38f6e06ae2c23c11cd0ea75ce033a0f025576167872a29a4207a316330443b28a372a9d5f3cada024ac442
ssdeep: 24576:orJwBbi/vlrJNltYba3v7vZ/b4gHaPcpgchCPpTg2YnosMLF:oWeGa3DRWeCPpTDCWp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16555D027A6C16832C353163859071A6BEA397E142AE4A5A76FE42D4FDF3035EF12C347
sha3_384: e90cd947d43bdb40a38f147257f8836fa5b4ce9516db637b7cb5110c6df399d4ad90d59d0b1f5b8f69feb9d386948121
ep_bytes: 558bec83c4f0535657b808451b13e8e9
timestamp: 2019-12-04 11:43:25

Version Info:

CompanyName: Hydra
FileDescription: AEW
FileVersion: 6.1.4.2
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: AEW
ProductVersion: 6.1.4.2
Comments:
Translation: 0x0409 0x04e4

Malware.AI.3609987981 also known as:

BkavW32.Common.9080B21B
LionicTrojan.Win32.Agent.lhuB
MicroWorld-eScanTrojan.Bandok.Gen.1
FireEyeGeneric.mg.ff24f75b7bb6c426
ALYacBackdoor.RAT.Bandook
MalwarebytesMalware.AI.3609987981
VIPRETrojan.Bandok.Gen.1
SangforSpyware.Win32.Agent.Vsnh
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/BadCert.72d321a4
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.36738.qL1@aOoWmofO
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.LXILJBH
KasperskyHEUR:Trojan-Spy.Win32.Agent.gen
BitDefenderTrojan.Bandok.Gen.1
NANO-AntivirusTrojan.Win32.Bandok.glrbyv
AvastWin32:Malware-gen
EmsisoftMalCert.E (A)
ZillyaTrojan.Agent.Win32.1220095
TrendMicroTROJ_FRS.0NA103LH19
McAfee-GW-EditionArtemis!Trojan
SophosMal/BadCert-Gen
GDataTrojan.Bandok.Gen.1
JiangminTrojanSpy.Agent.adov
WebrootW32.Malware.Gen
GoogleDetected
MAXmalware (ai score=100)
Antiy-AVLGrayWare/Win32.Generic
Kingsoftmalware.kb.a.995
ArcabitTrojan.Bandok.Gen.1
ZoneAlarmHEUR:Trojan-Spy.Win32.Agent.gen
MicrosoftTrojan:Win32/Casdet!rfn
CynetMalicious (score: 100)
VBA32TrojanSpy.Agent
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103LH19
RisingTrojan.Generic@AI.80 (RDMK:ehM01Uf24CR5Z8MwnAx2lg)
IkarusTrojan.SuspectCRC
FortinetW32/Injector.fam!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.3609987981?

Malware.AI.3609987981 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment