Malware

Malware.AI.3700036811 removal

Malware Removal

The Malware.AI.3700036811 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3700036811 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Executed a sysinternals tool

How to determine Malware.AI.3700036811?


File Info:

name: 272D2D246A9D3E0E8797.mlw
path: /opt/CAPEv2/storage/binaries/b8f008534cba7cbf49a1fe3561943144b499331b9dcbb4a1c5812861d1a26dc5
crc32: 24C4F772
md5: 272d2d246a9d3e0e87977570fd2e5ca5
sha1: 534b855b4394cd0b1c87a84706cc3ba385bcf46e
sha256: b8f008534cba7cbf49a1fe3561943144b499331b9dcbb4a1c5812861d1a26dc5
sha512: 567796b3339fad8bbec71f03074f5d2e4ca412f01054a1a36fe3bf119acfd8afd60623445138ea12f8e47c30c33e4768334c39f38fd7158a00d05ebe1593ab96
ssdeep: 12288:XFt4rcDsld/SFo9GlMV0UPkxRGk5e3fbbREgC8V8tyN8:rGc8BUjl20UPYGk5ePbygCIP8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F115D01132D0C031ED5A25F1457AC7B25E7A78F55B279ACF67E0B6BD0E213E0AA39309
sha3_384: 8699a8a9edef22abb83f9807563cedaa68ac135a8483dd81f973f135e1839f5ead813ee1d45d7f4ec138b11ba360cb3f
ep_bytes: 558bec6aff6898954000689c37400064
timestamp: 2021-10-07 05:18:35

Version Info:

CompanyName: Matrix
FileDescription: DebugView
FileVersion: 4.76
InternalName: Sysinternals Debug Output Viewer
LegalCopyright: Copyright ? 1998-2008 Mark Russinovich
OriginalFilename: Dbgview.exe
ProductName: MatrixDebugview
ProductVersion: 4.76
Translation: 0x0409 0x04b0

Malware.AI.3700036811 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Jaik.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.48380
FireEyeGeneric.mg.272d2d246a9d3e0e
McAfeeArtemis!272D2D246A9D
MalwarebytesMalware.AI.3700036811
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/Kryptik.755314d4
K7GWTrojan ( 00588b3e1 )
K7AntiVirusTrojan ( 00588b3e1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMUW
TrendMicro-HouseCallTROJ_GEN.R002H0CJH21
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderGen:Variant.Jaik.48380
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Jaik.48380
EmsisoftGen:Variant.Jaik.48380 (B)
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.xhgvl
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.BSE.TTUNZ7
AhnLab-V3Trojan/Win.Generic.R445985
Acronissuspicious
VBA32BScope.TrojanSpy.Bobik
ALYacGen:Variant.Jaik.48380
MAXmalware (ai score=86)
APEXMalicious
TencentWin32.Trojan.Jaik.Hpij
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HMUW!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.b4394c

How to remove Malware.AI.3700036811?

Malware.AI.3700036811 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment