Malware

Malware.AI.3688386817 malicious file

Malware Removal

The Malware.AI.3688386817 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3688386817 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Attempts to stop active services
  • A possible heap spray exploit has been detected
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Malware.AI.3688386817?


File Info:

name: 3955477F0E972DA81126.mlw
path: /opt/CAPEv2/storage/binaries/2d2019e192f27abefaa85a002637d406920f0607245b591c03a0cc7f897bb42e
crc32: 5164AB17
md5: 3955477f0e972da81126af5d4c137e1d
sha1: 68506007b26aaae7a750a3069279f94a14ca9ed1
sha256: 2d2019e192f27abefaa85a002637d406920f0607245b591c03a0cc7f897bb42e
sha512: 36e2dea49f2ae684b6b56967dae06429e640615094108929bf99e64ee2f0950fb299e5df5fd117d9bc05dd2620a56ac89ec9bb705135b04a7601b15b630ed7fe
ssdeep: 24576:BehZfTRMPqQQwkz5cApVS/SoBm2xzGJEfZ0dbXnclvzlerxf33KNdueACYLzQk3:07flMQTaApVb2xzGJ/dbMlp2xf33KNdy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155652395F290E4D4C8A375B2DA6AC7FA41457D2EEB45094324E93F2B39728C30E35D87
sha3_384: 9634547728d9d060232d68ce1fabfc076b5335f440e090c41578b603c40ee4ca116b2d984aa0c10b556d40b096970548
ep_bytes: 60be000060008dbe0010e0ff5789e58d
timestamp: 2021-12-28 09:51:22

Version Info:

0: [No Data]

Malware.AI.3688386817 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Agent.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.8027
FireEyeGeneric.mg.3955477f0e972da8
McAfeeGenericRXAA-AA!3955477F0E97
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaMalware:Win32/km_2806a9.None
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.f0e972
BitDefenderThetaGen:NN.ZexaF.34212.AnIfaC2JdMbb
CyrenW32/StartPage.CR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Barys-9937004-0
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Barys.8027
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10cff5df
Ad-AwareGen:Variant.Barys.8027
EmsisoftGen:Variant.Barys.8027 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.RKIT/Agent.lbwqw
DrWebTrojan.Fakealert.59686
ZillyaAdware.Agent.Win32.171217
TrendMicroTROJ_GEN.R002C0DAV22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Behav-004
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.5LSHNI
JiangminAdware.Agent.aubl
eGambitUnsafe.AI_Score_100%
AviraRKIT/Agent.lbwqw
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.FlyStudio.a
GridinsoftRansom.Win32.Sabsik.oa!s2
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.gen
MicrosoftTrojan:Win32/Startpage.AGM
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R435497
Acronissuspicious
VBA32Rootkit.Agent
ALYacGen:Variant.Barys.8027
MalwarebytesMalware.AI.3688386817
TrendMicro-HouseCallTROJ_GEN.R002C0DAV22
RisingTrojan.StartPage!8.B (CLOUD)
YandexPUA.Agent!y0+5oPzJ4C8
IkarusTrojan.Rootkit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.3688386817?

Malware.AI.3688386817 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment