Malware

Malware.AI.3694940386 information

Malware Removal

The Malware.AI.3694940386 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3694940386 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Likely installs a bootkit via raw harddisk modifications
  • Attempted to write directly to a physical drive

How to determine Malware.AI.3694940386?


File Info:

name: 5A134AD92F8B7817FC23.mlw
path: /opt/CAPEv2/storage/binaries/20cf7b047ed5606d35b7658e6bf6a63e602d3ca3af7ac8ddf300fe471075bac7
crc32: D3E67CF3
md5: 5a134ad92f8b7817fc230dfaa05107ed
sha1: 8a1e0a3966b7427d0ddc839ed01979f60d1ce069
sha256: 20cf7b047ed5606d35b7658e6bf6a63e602d3ca3af7ac8ddf300fe471075bac7
sha512: 6dc5b723d5fb2dedee455c2bd4c449f292ea59eaebb2a7e3b1483bf1e43f3834ad944da3cd9721bd8bdb88b5e997b39912285438805fe861f7f07a645a00ee41
ssdeep: 3072:ZVZ/VGS7rN+0h97TKmhjwgYAejkFox0out:ZV28oA97T5qgYHB0oS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108A3020AE0C9AB6EC964D57B595F2C67AD8EC75C37C09121D7E133B26C926068BCC336
sha3_384: e7548d40c112f50bcda4321e32aef31348bc1a1fa9662e17d22d772b6969df8d32c5e59edb7cb06387d28ce8cf506caf
ep_bytes: 60be151041008dbeebfffeff5789e58d
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Malware.AI.3694940386 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.38879085
ALYacTrojan.GenericKD.38879085
MalwarebytesMalware.AI.3694940386
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.38879085
K7GWTrojan ( 0051918e1 )
K7AntiVirusTrojan ( 0051918e1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/KillDisk.NCU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.KillMBR.gsl
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareTrojan.GenericKD.38879085
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WBJ22
FireEyeGeneric.mg.5a134ad92f8b7817
EmsisoftTrojan.GenericKD.38879085 (B)
IkarusTrojan.PSW.Stealer
AviraTR/KillDisk.srnto
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.2B9EB3B
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D2513F6D
GDataTrojan.GenericKD.38879085
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!5A134AD92F8B
VBA32Trojan.Sabsik.FL
CylanceUnsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WBJ22
TencentMalware.Win32.Gencirc.10ce4679
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.966b74
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3694940386?

Malware.AI.3694940386 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment