Malware

Should I remove “Malware.AI.3654281408”?

Malware Removal

The Malware.AI.3654281408 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3654281408 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3654281408?


File Info:

name: EC3A78BD0A12F67E75F6.mlw
path: /opt/CAPEv2/storage/binaries/d3bed331ce454d3134f77ccfbe8e77761720c042acb28ab78196c1ba1501c120
crc32: 4A34960E
md5: ec3a78bd0a12f67e75f6d97518b97eeb
sha1: 79378dc544d82039d9133b8eafd9d9f53636bc6b
sha256: d3bed331ce454d3134f77ccfbe8e77761720c042acb28ab78196c1ba1501c120
sha512: 197f11a7e694cc05b3b11ba81a575e6d6ddac227835de86872d1208fa6eb133e6621d87caec5c35ad7e9a67305fac2c2ce3e8fb14ad6f39ddc89c4316144c93e
ssdeep: 98304:d/a/nXJZM346QzBCMJHvts3/sWhsapHdkeYAWp+Xz:1a/ZZ046QQMJHvts3v2apee3Sk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15436339D6B19DC24C8F7A6F8DE9AF5F1A2492D50D802497361B0BEC3F8F2C2D6C05A11
sha3_384: 324b76547c54a737dc83be1caf39fefc33538e567acf69cc9406332c788fb0206aba6da8e4f25106e0bf43e42bb53b1f
ep_bytes: e89738bbff981a6cd02e84347a991ac4
timestamp: 2013-06-19 14:22:47

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: M2LTLogin.exe
LegalCopyright: TODO: (C) 。保留所有权利。
OriginalFilename: M2LTLogin.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0804 0x03a8

Malware.AI.3654281408 also known as:

LionicRiskware.Win32.Snojan.1!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.ec3a78bd0a12f67e
SkyhighBehavesLike.Win32.BadFile.rc
MalwarebytesMalware.AI.3654281408
SangforDownloader.Win32.Snojan.Vo9o
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaDownloader:Win32/Snojan.9f535e03
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderThetaGen:NN.ZexaF.36792.@F0@aGOvuPaj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.Snojan.heev
AvastFileRepMalware [Trj]
SophosGeneric ML PUA (PUA)
Trapminemalicious.moderate.ml.score
Antiy-AVLRiskWare[Downloader]/Win32.Snojan
ZoneAlarmnot-a-virus:Downloader.Win32.Snojan.heev
McAfeeArtemis!EC3A78BD0A12
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002V01KE23
RisingTrojan.Generic@AI.100 (RDML:JtEzL2lPJ6seYpjY11bHMA)
SentinelOneStatic AI – Suspicious PE
AVGFileRepMalware [Trj]
Cybereasonmalicious.544d82
DeepInstinctMALICIOUS

How to remove Malware.AI.3654281408?

Malware.AI.3654281408 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment