Malware

Malware.AI.3671672174 removal tips

Malware Removal

The Malware.AI.3671672174 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3671672174 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

www.pubyun.com
ok.mymyxmra.ru
wpad.local-net
xmr.xmr5b.ru

How to determine Malware.AI.3671672174?


File Info:

name: 55BF82C59C7BF17629E4.mlw
path: /opt/CAPEv2/storage/binaries/e90357a012382cb8359c69eee6177a79666ba90030c5f62a0f29149cd9970ed0
crc32: A002CBF8
md5: 55bf82c59c7bf17629e4b054c0f2439d
sha1: c09c496f2b32d213478c2c5476a739711f029aaa
sha256: e90357a012382cb8359c69eee6177a79666ba90030c5f62a0f29149cd9970ed0
sha512: fdd422480195c982f7158fba012574563552b6ce19e2dce6c7791e781d6178df6d92ccd91f22622d94747bce7e6a37a8b518acdd354e8b2273bb2ee87ccdef4a
ssdeep: 24576:Voyc+VIEIWINKryQNnirKxxD29ARCiTZXqAv2VRu2zDqjD3:VoXUICCENnirKb9PN6TU2PqH3
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1D0358C5EAA5405F6C476C0B8C8127046E3B1B45A1BB187EB4FE6736E5F23AE15E3E310
sha3_384: 7542b2834f08459a0bd3f6381838253244f6e343882773e95b25152cddbac7ea8a6935ecde4ea519fa30c08eed014f78
ep_bytes: 4883ec28e83b0600004883c428e976fe
timestamp: 2018-03-21 20:14:32

Version Info:

0: [No Data]

Malware.AI.3671672174 also known as:

LionicRiskware.Win32.BitCoinMiner.1!c
FireEyeGeneric.mg.55bf82c59c7bf176
McAfeeArtemis!55BF82C59C7B
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win64.3756
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005178441 )
AlibabaTrojanDownloader:Win64/CoinMiner.b74f50f8
K7GWTrojan ( 005178441 )
SymantecPUA.Gen.2
ESET-NOD32a variant of Win64/CoinMiner.EM
TrendMicro-HouseCallPUA_COINMINE.SMALY
Paloaltogeneric.ml
ClamAVWin.Trojan.Bitminer-9819753-0
KasperskyTrojan-Downloader.Win32.Agent.xxzuhz
AvastWin32:XMRStak-A [Miner]
TencentMalware.Win32.Gencirc.11db3c4f
SophosXMR-Stak Miner (PUA)
TrendMicroPUA_COINMINE.SMALY
McAfee-GW-EditionBehavesLike.Win64.PUP.th
IkarusPUA.CoinMiner
GDataWin64.Trojan.Agent.5OJ9LY
JiangminRiskTool.Miner.lw
AviraTR/CoinMiner.xoggj
Antiy-AVLTrojan/Generic.ASMalwS.34D6DBC
GridinsoftRansom.Win64.Gen.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Win-Trojan/Miner3.Exp
MalwarebytesMalware.AI.3671672174
YandexTrojan.DL.Agent!jK5jl4xNCJs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.131197022.susgen
FortinetAdware/Miner
AVGWin32:XMRStak-A [Miner]
Cybereasonmalicious.f2b32d

How to remove Malware.AI.3671672174?

Malware.AI.3671672174 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment