Malware

Malware.AI.3682198803 malicious file

Malware Removal

The Malware.AI.3682198803 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3682198803 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a command line with /V argument which modifies variable behaviour and whitespace allowing for increased obfuscation options
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script process created a new process
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Malware.AI.3682198803?


File Info:

name: FCC102B5AA90355934EA.mlw
path: /opt/CAPEv2/storage/binaries/2a99827d5dd43ce8654cd0dd28a02561d20d9aa10de08419efc4ddeca4b50a59
crc32: C8D71510
md5: fcc102b5aa90355934eaa06b4d85ed57
sha1: fb24c810e286f6abe0f9f6b8c4bf7568c319f28a
sha256: 2a99827d5dd43ce8654cd0dd28a02561d20d9aa10de08419efc4ddeca4b50a59
sha512: b6476dd86d1e4a7ac400297854369c40ebe81ea60642653fd83934becd71f7e41ab5e1e1b97809d97ccd0a44437e4f9fc402c4d76ecbe847f450bd0daa9e22ce
ssdeep: 24576:U2G/nvxW3Ww0tZ7m0EhyBzlltDkwLyHVE8PfNsZxQj+4o:UbA30jyyBzloowE82xQy1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA454A127A84CE12D12A1A3BC5EF405447BCFD016A62DB1B7EAE33AD65123A35E0D5CF
sha3_384: 970940a4008761abbbd5a6a94eb3c4a700221d9d77e007a1e8a296840ac412b0bda79c9710a209df46c786f9e49ea252
ep_bytes: e874040000e988feffff3b0d68e64300
timestamp: 2020-12-01 18:00:55

Version Info:

0: [No Data]

Malware.AI.3682198803 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.QuasarNET.5
MicroWorld-eScanTrojan.Uztuby.19
FireEyeGeneric.mg.fcc102b5aa903559
ALYacIL:Trojan.MSILZilla.9872
SangforTrojan.Win32.Save.a
Cybereasonmalicious.5aa903
BitDefenderThetaAI:Packer.A84F0F3A26
CyrenW32/MSIL_Agent.LQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
Paloaltogeneric.ml
ClamAVWin.Malware.Uztuby-9848412-0
KasperskyUDS:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.Uztuby.19
AvastWin32:SpywareX-gen [Trj]
Ad-AwareIL:Trojan.MSILZilla.9872
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftTrojan.Uztuby.19 (B)
SentinelOneStatic AI – Malicious SFX
GDataWin32.Trojan.BSE.1CL7UZW
AviraHEUR/AGEN.1144842
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!FCC102B5AA90
MalwarebytesMalware.AI.3682198803
APEXMalicious
FortinetMSIL/Agent.DEK!tr.spy
AVGWin32:SpywareX-gen [Trj]

How to remove Malware.AI.3682198803?

Malware.AI.3682198803 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment