Malware

Malware.AI.3646749662 (file analysis)

Malware Removal

The Malware.AI.3646749662 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3646749662 virus can do?

  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.3646749662?


File Info:

name: 68119EBC38F898BE0E7B.mlw
path: /opt/CAPEv2/storage/binaries/1224178fec01e7428dd5ce6feaf9c5dd99f4ff04a7d8fc55519f412b0cc7da48
crc32: AB0FA5FE
md5: 68119ebc38f898be0e7ba21f2d3f53cc
sha1: 4bdc6fc56a63191d1ce1fabc13499feebc1ae464
sha256: 1224178fec01e7428dd5ce6feaf9c5dd99f4ff04a7d8fc55519f412b0cc7da48
sha512: 1222dd9c4df2ab56b238e59f313d3c53e8bbb7c3583d26650bffbbaf6c32a2299efc375ce28d4ae7ac85bb07f4b62466ef352d6584307c774de97026464b9910
ssdeep: 768:XEIEFZ0+5TnW5MGvb6TNpC6CBdfd5s4i:0I4Z0+5TnW5MGvb6TNpEndq4i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3B2C60873F46E25E1BD8AB65EF0900403B7B557C562E60F0E4B644E09B37A8DE61FA7
sha3_384: a8bdca34bc8edcda67dfa9e52dbf6dc1470e6b19bba04021b70ad3c66a812b71972c14db704f5a1e760331c5c9b3c4ea
ep_bytes: ff250020400000000000000000000000
timestamp: 2075-01-21 06:23:35

Version Info:

Translation: 0x0000 0x04b0
Comments: Хост-процесс для задач Windows
CompanyName:
FileDescription: Хост-процесс для задач Windows
FileVersion: 10.0.19041.906
InternalName: taskhostw.exe
LegalCopyright: © Корпорация Майкрософт Вселенная
LegalTrademarks:
OriginalFilename: taskhostw.exe
ProductName: Операционная система Microsoft
ProductVersion: 10.0.19041.906
Assembly Version: 10.0.19041.906

Malware.AI.3646749662 also known as:

LionicTrojan.Multi.GenericML.4!c
MicroWorld-eScanTrojan.GenericKD.38874115
FireEyeGeneric.mg.68119ebc38f898be
ALYacTrojan.GenericKD.38874115
MalwarebytesMalware.AI.3646749662
ZillyaTrojan.Agent.Win32.2618876
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 0058e7651 )
AlibabaTrojan:MSIL/Generic.c076a470
K7GWTrojan ( 0058e7651 )
Cybereasonmalicious.c38f89
BitDefenderThetaGen:NN.ZemsilF.34212.bm0@au3XSxg
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Agent.DRW
APEXMalicious
BitDefenderTrojan.GenericKD.38874115
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Ursu.Wncj
Ad-AwareTrojan.GenericKD.38874115
EmsisoftTrojan.GenericKD.38874115 (B)
TrendMicroTROJ_GEN.R002C0PA722
McAfee-GW-EditionRDN/Generic.rp
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
GDataTrojan.GenericKD.38874115
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1203743
Antiy-AVLTrojan/Generic.ASMalwS.34FF2AE
ArcabitTrojan.Generic.D2512C03
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4928524
McAfeeRDN/Generic.rp
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PA722
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.139759814.susgen

How to remove Malware.AI.3646749662?

Malware.AI.3646749662 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment