Malware

Malware.AI.3613136714 removal tips

Malware Removal

The Malware.AI.3613136714 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3613136714 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Malware.AI.3613136714?


File Info:

name: 409627A4EFE14ACA6176.mlw
path: /opt/CAPEv2/storage/binaries/4d0fd9c9c7423a8f3d689f8c15735a184f3f0b1d3cdab52c53829ddc103e8344
crc32: 0A2991ED
md5: 409627a4efe14aca6176fbc597ea373e
sha1: 6f425502fa14fb0892622f3cdb4b4c1f1cc2ae9c
sha256: 4d0fd9c9c7423a8f3d689f8c15735a184f3f0b1d3cdab52c53829ddc103e8344
sha512: e4e40de2ec8ff13438980f28d48434941874120e7666277ecb4359e3320fc55358d2d9a8cc0d5abd2abffc48db97d7c138fd6b5cc0499fc6586e5499312d47f6
ssdeep: 1536:pcpZO4kRqFKlSrW4HcOlbUUQGqoFnToIf0MnN1Hv/u:x4kRWKlSrjZUUQGqotTBf0GN1O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154639E42A78084D3E0D425B0F1E9E63EEF7A76750A6891AB67A2F75D2C25301F731387
sha3_384: ddc8f095e1fb4226e05792887f4f4fee97c4a835f8e54f6ed408ee7ed1a9c0b206eb9309d259def3c82f694161c632c7
ep_bytes: 558bec6aff686821400068901b400064
timestamp: 2013-08-29 08:00:33

Version Info:

Comments:
CompanyName:
FileDescription: Microsoft Corporation
FileVersion: 1, 0, 0, 1
InternalName: Microsoft Desktop
LegalCopyright: 版权所有(C) 2012
LegalTrademarks:
OriginalFilename: Microsoft Desktop
PrivateBuild:
ProductName: Microsoft Desktop
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.3613136714 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.122673
FireEyeGeneric.mg.409627a4efe14aca
ALYacGen:Variant.Fragtor.122673
CylanceUnsafe
VIPREGen:Variant.Fragtor.122673
Sangfor[ARMADILLO V1.71]
Cybereasonmalicious.4efe14
ESET-NOD32a variant of Win32/Farfli.AOF
APEXMalicious
KasperskyBackdoor.Win32.Nbdd.ojt
BitDefenderGen:Variant.Fragtor.122673
NANO-AntivirusTrojan.Win32.Nbdd.cwzkgb
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic@AI.88 (RDMK:cmRtazr8REfClGWNswB4yJh453zV)
Ad-AwareGen:Variant.Fragtor.122673
EmsisoftGen:Variant.Fragtor.122673 (B)
DrWebTrojan.DownLoader10.30804
ZillyaBackdoor.Nbdd.Win32.2240
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.122673
JiangminHeur:Backdoor/Huigezi
GoogleDetected
AviraHEUR/AGEN.1214931
Antiy-AVLTrojan/Generic.ASMalwS.225
ArcabitTrojan.Fragtor.D1DF31
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Nbdd.C254874
McAfeeArtemis!3C7E67FE058D
MAXmalware (ai score=82)
VBA32BScope.Trojan.Agentb
MalwarebytesMalware.AI.3613136714
YandexBackdoor.Nbdd!Km/a1fRJiis
MaxSecureTrojan.Malware.6478627.susgen
BitDefenderThetaGen:NN.ZexaF.34592.em2@auAtMpgb
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3613136714?

Malware.AI.3613136714 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment