Malware

What is “Malware.AI.369369740”?

Malware Removal

The Malware.AI.369369740 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.369369740 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Malware.AI.369369740?


File Info:

name: 3705518294834D704767.mlw
path: /opt/CAPEv2/storage/binaries/3ee1799f1e5e7c2e65cba35e88a2e0d0127db3c1613a7271b2f611a32ad03c15
crc32: D8A21318
md5: 3705518294834d704767c069476dff69
sha1: 68cc01462d67a6716870f709f9abcb925cab5d94
sha256: 3ee1799f1e5e7c2e65cba35e88a2e0d0127db3c1613a7271b2f611a32ad03c15
sha512: 126686d64226d63d172ee6c3fdd6e6a89eebcaa4d48ab00d991f1fa98e020cf9494d1f0266181c62536f0b15e92400eac03cf2dbe10efc405d681748264ce2c2
ssdeep: 96:56JbC4clhXEpEbvQcZAIKrmsqC8KpenHy7hhlhfJ+WjiIek:5wenvOHfqC8K8nHyJhkC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B3D1920A57DD037BE8BA4B7C68B303032378E5555E23DB1E1DC8026E28A4B458F32BD9
sha3_384: d4fca4a0effd8acdd2fe071770e3be21bccca99be04d93f2e7ac25385f9674226cce72bcfb1cb452313e5c421a1368e5
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-04-21 23:48:08

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: cspsvc.exe
LegalCopyright:
OriginalFilename: cspsvc.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Malware.AI.369369740 also known as:

LionicTrojan.MSIL.Miner.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.6646
FireEyeIL:Trojan.MSILZilla.6646
ALYacIL:Trojan.MSILZilla.6646
ZillyaTrojan.Miner.Win32.3678
K7AntiVirusTrojan ( 00534cc31 )
K7GWTrojan ( 00534cc31 )
Cybereasonmalicious.294834
CyrenW32/Trojan.CBH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.SPP
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Johnnie-9830068-0
KasperskyTrojan.MSIL.Miner.aim
BitDefenderIL:Trojan.MSILZilla.6646
NANO-AntivirusTrojan.Win32.Miner.iuubip
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.CspMiner!1.C2FE (CLASSIC)
SophosMal/Generic-R
ComodoTrojWare.MSIL.Miner.GU@8ghwjr
DrWebTrojan.Starter.7713
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.MSIL.SERVSTAR.SMAA
McAfee-GW-EditionBehavesLike.Win32.Trojan.xt
EmsisoftIL:Trojan.MSILZilla.6646 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1208692
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/CoinMiner.SA
GDataIL:Trojan.MSILZilla.6646
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C2671981
McAfeeGenericRXFX-YM!370551829483
MalwarebytesMalware.AI.369369740
TrendMicro-HouseCallTrojan.MSIL.SERVSTAR.SMAA
TencentMsil.Trojan.Miner.Lhmz
YandexTrojan.Miner!DRROAuXFzpI
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.73391618.susgen
FortinetMSIL/CoinMiner.SPP!tr
BitDefenderThetaGen:NN.ZemsilF.34182.am0@aO4aYah
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.369369740?

Malware.AI.369369740 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment