Malware

What is “Malware.AI.3655038949”?

Malware Removal

The Malware.AI.3655038949 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3655038949 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3655038949?


File Info:

name: 534777EB72AC02A47FEB.mlw
path: /opt/CAPEv2/storage/binaries/b87c3c31e5dff894d401bd889343530376e80a532603a04d36f05b58e1150cee
crc32: 3D1E06CE
md5: 534777eb72ac02a47feb788422a4813e
sha1: c8b35767c4d785096f2d21343015d2ad1a88e256
sha256: b87c3c31e5dff894d401bd889343530376e80a532603a04d36f05b58e1150cee
sha512: 642975ee30d847f57c9c33ce535c6ea178e2fe9a66890cf5e3effcbb530a0368c0ddafe4a6de13c6c6c3ae2c47040403f2300010b035bbb6c7c4ffd8e98d6ef2
ssdeep: 24576:c64MVTDmAtRtnmiXempRG33LeebLNdlq5NULVJPfVXMB7FAsctaXyVf32GGqygOH:c64MTSAdmUpINdke3PfaBBAscUE2OM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F65339612888A30C47808788FA9EA54175F7D755B9A463B5EFC3C2EADB43D3391138F
sha3_384: 1652caf2f5568ebbce956d1832aadae6f88a96ef130726d479e8ba859301e8399350d52b1242b6fe9a42dfc471b922b8
ep_bytes: 6800144000e8f0ffffff000000000000
timestamp: 2008-09-27 18:37:31

Version Info:

CompanyName: Arab Team 4 Reverse Engineering - www.at4re.com
FileDescription: System Analyzing Tool
FileVersion: 1.3.1
InternalName: Kernel Detective
LegalCopyright: Copyright (C) 2008 - 2009
OriginalFilename: Kernel Detective.exe
ProductName: Kernel Detective
ProductVersion: 1.3.1
Translation: 0x0809 0x04b0

Malware.AI.3655038949 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Ardamax.lmIa
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.824963
FireEyeGeneric.mg.534777eb72ac02a4
CAT-QuickHealTrojan.Ardamax.A
ALYacGen:Variant.Bulz.824963
CylanceUnsafe
VIPREGen:Variant.Bulz.824963
Sangfor[MICROSOFT VISUAL BASIC V6.0]
K7AntiVirusTrojan ( 0055e3df1 )
AlibabaTrojanDropper:Win32/ArdaSpy.be0d7790
K7GWTrojan ( 0055e3df1 )
Cybereasonmalicious.b72ac0
VirITTrojan.Win32.Generic.ANJX
CyrenW32/Trojan.SVLO-4317
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.OHG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Buzus-6934797-0
KasperskyTrojan-Spy.Win32.Zbot.vnoz
BitDefenderGen:Variant.Bulz.824963
NANO-AntivirusTrojan.Win32.Buzus.dhfks
ViRobotTrojan.Win32.Buzus.24576.BU
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10ba2d36
Ad-AwareGen:Variant.Bulz.824963
EmsisoftGen:Variant.Bulz.824963 (B)
ComodoTrojWare.Win32.Trojan.Buzus.~PL@12y4f
DrWebTrojan.MulDrop3.51721
ZillyaTrojan.Buzus.Win32.94551
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-E
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.824963
JiangminTrojan/Buzus.blaw
WebrootW32.Dropper.Gen
GoogleDetected
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.AA
ArcabitTrojan.Bulz.DC9683
MicrosoftMonitoringTool:Win32/Ardamax
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Buzus.C57945
Acronissuspicious
McAfeeGenericRXAA-AA!534777EB72AC
VBA32Malware-Cryptor.VB.gen.1
MalwarebytesMalware.AI.3655038949
RisingTrojan.Win32.Buzus.zwd (CLASSIC)
YandexTrojan.GenAsa!xGAR9rDcXUM
IkarusVirus.Win32.Vtub
MaxSecureHoax.ArchSMS.loaf
FortinetW32/Buzus.ZWD!tr
BitDefenderThetaGen:NN.ZexaF.34592.jvW@aCIgKV3T
AVGWin32:Malware-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3655038949?

Malware.AI.3655038949 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment