Malware

Should I remove “Malware.AI.3712708638”?

Malware Removal

The Malware.AI.3712708638 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3712708638 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Vietnamese
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3712708638?


File Info:

name: E88791836FC204FFAAE4.mlw
path: /opt/CAPEv2/storage/binaries/d2cc0209b78006360344f79009b92fe64eb431716c6a66125e78cf8bd08847cb
crc32: AD07D349
md5: e88791836fc204ffaae446c6a5cb67bf
sha1: af58cf9b3b15b97e0d6c413f910ad8e2d42ac346
sha256: d2cc0209b78006360344f79009b92fe64eb431716c6a66125e78cf8bd08847cb
sha512: e63d3ebb43bd5ca3a7cddfc06a3828a3be87ed7e94830b772fe5954406652f582728f3efa98c10e2d12d3dc75bace33b6a4b0cfed0947d9d56e3404e698c8bd6
ssdeep: 49152:hTvC/MTQYxsWR7aqNvZj7M8xOxAsvgvWLh2dx5El5J:9jTQYxsWRZu8QGTvWLh2d45
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDC5020273919062FF9B96330F96F7115BBC6A660123E62F13981D79BE704B1463E7A3
sha3_384: aabde07416c360f175c502f649199b6c53ef57c8ddbd2b232efc60be92e1f77dee76c7c0bcfadaa0f56c930c40cdca70
ep_bytes: e86e050000e97afeffff558bec56ff75
timestamp: 2023-07-12 12:50:57

Version Info:

FileVersion: 3.1.0
Comments: Play Togetger Trúc Xinh
FileDescription: Trúc Xinh
ProductName: Trúc Xinh
ProductVersion: 3.1.0
CompanyName: Trúc Xinh
LegalCopyright: Tool Trúc Xinh
LegalTradeMarks: Trúc Xinh
Translation: 0x042a 0x04b0

Malware.AI.3712708638 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win64.Injects.ts93
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.5059
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!E88791836FC2
Cylanceunsafe
SangforTrojan.Win32.Save.a
BitDefenderThetaGen:NN.ZexaF.36680.Bw0@aKXNW0nO
CynetMalicious (score: 100)
BitDefenderAIT:Trojan.Nymeria.5059
AvastWin32:Malware-gen
SophosMal/Generic-S
VIPREAIT:Trojan.Nymeria.5059
EmsisoftAIT:Trojan.Nymeria.5059 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Script.awbz
GoogleDetected
ArcabitAIT:Trojan.Nymeria.D13C3
GDataAIT:Trojan.Nymeria.5059
VaristW32/ABRisk.DBYH-8215
ALYacAIT:Trojan.Nymeria.5059
MalwarebytesMalware.AI.3712708638
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09GJ23
MaxSecureTrojan.Malware.191448165.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.3712708638?

Malware.AI.3712708638 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment