Malware

Malware.AI.3612074219 (file analysis)

Malware Removal

The Malware.AI.3612074219 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3612074219 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.3612074219?


File Info:

name: B6E2490992BA2E2AC6DA.mlw
path: /opt/CAPEv2/storage/binaries/c82f7afcc4ed93eee2ea1485a47e4a0c8c01ff7e58fa4188b525a97d65049683
crc32: 049BEE8B
md5: b6e2490992ba2e2ac6da0f7fa4d64f42
sha1: 72d2ac6ba9ecfede423e7410fd6a90ce85ec7fa6
sha256: c82f7afcc4ed93eee2ea1485a47e4a0c8c01ff7e58fa4188b525a97d65049683
sha512: cc5697d055738b736e63990a2888d4836b1adec6f7eb98ef22d4b36ab855ae96320989d29d2eb09147e2f45ec91bbac79a0800abdfa8d56543d8cdc478f14c0d
ssdeep: 6144:FoL09NPK6moL09NPK6moL09NPK6moL09NPK6moL09NPK6moL09NPK6/xH/K2jye:vzC6MzC6MzC6MzC6MzC6MzC6/xH/d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D615A0896F2977D1CDDE16B9C170E52DF030ACC4871E556EDB073EC989313A09AAB18E
sha3_384: 4bfc6ddf17871d3b933bdad4c4039e27b51c96c7d6b43aa80d405526d47c730cbfa7b31a37e89c3cf7bd29d3e0e2579a
ep_bytes: e8fb5f0000e82b600000e85c600000e8
timestamp: 2011-04-03 12:07:51

Version Info:

0: [No Data]

Malware.AI.3612074219 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ransom.GandCrab.2479
FireEyeGeneric.mg.b6e2490992ba2e2a
SkyhighBehavesLike.Win32.PolyPatch.dz
McAfeePolyPatch-UPX
MalwarebytesMalware.AI.3612074219
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Ransom.GandCrab.2479
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.36802.5mZ@aaPntmgi
SymantecW32.Suviapen
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Agent.NFD
APEXMalicious
AvastWin32:Agent-BCFZ [Trj]
EmsisoftGen:Variant.Ransom.GandCrab.2479 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Siggen9.43023
VIPREGen:Variant.Ransom.GandCrab.2479
Trapminemalicious.moderate.ml.score
SophosML/PE-A
IkarusTrojan.Win32.Krypt
JiangminTrojan.Generic.eqhsh
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLVirus/Win32.Sivis
Kingsoftmalware.kb.a.981
ArcabitTrojan.Ransom.GandCrab.D9AF
CynetMalicious (score: 100)
VBA32BScope.Trojan.Cosmu
Cylanceunsafe
RisingTrojan.GenKryptik!8.AA55 (TFE:4:kSFsHYqhDqQ)
YandexTrojan.GenAsa!8BX67dEhxck
SentinelOneStatic AI – Malicious PE
FortinetW32/Ausiv.A
AVGWin32:Agent-BCFZ [Trj]
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Visua.A(dyn)

How to remove Malware.AI.3612074219?

Malware.AI.3612074219 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment