Malware

What is “Malware.AI.3712959942”?

Malware Removal

The Malware.AI.3712959942 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3712959942 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Arabic (Algeria)
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3712959942?


File Info:

name: 2C10BF9448808066510E.mlw
path: /opt/CAPEv2/storage/binaries/172b300091230aa0e3799a0f966554f083bc67fde5609ae1c81b6fa2b701d29f
crc32: 8AE62140
md5: 2c10bf9448808066510ed1e0da23fc46
sha1: 84e0f3c96047309b8d061daec852a703061a22fb
sha256: 172b300091230aa0e3799a0f966554f083bc67fde5609ae1c81b6fa2b701d29f
sha512: 7b661417924dbf6d60fdc4d5cd296812fc18f7730f5c2b6b37bbee95126a21c502e81c7d9d3eee3eaae91da64aad018a9ed46bd1d947ef483858d38be349ff22
ssdeep: 12288:HtRB+k673NYpdlwXW8dBZSbE+VHl/LBQa+m1tCE/4RgrDae5:HtRB273gqBUJVF/l1Vjrue5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15865F112B6F8467CF0F36B30A875A7519939BC33CA25977E069005AD1E31981AF21FB7
sha3_384: 97d9593358ced562be9844a9bc8b3e6b87cd0642775652e3ed75116289d34a8b69a0e68eceab363b590a453069c54bf4
ep_bytes: e826050000e98efeffff558bec6a00ff
timestamp: 2018-05-08 22:44:45

Version Info:

CompanyName: Google Inc.
FileDescription: Google Installer
FileVersion: 1.3.33.17
InternalName: Google Update
LegalCopyright: Ауторска права 2007–2010. Google Inc.
OriginalFilename: GoogleUpdate.exe
ProductName: Google ажурирање
ProductVersion: 1.3.33.17
Translation: 0x081a 0x04e2

Malware.AI.3712959942 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Waldek.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!2C10BF944880
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058c7011 )
AlibabaVirus:Win32/Expiro.a3551dbc
K7GWTrojan ( 0058c7011 )
Cybereasonmalicious.960473
BitDefenderThetaGen:NN.ZexaF.34114.xz0@aWT@i6dP
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
KasperskyUDS:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
McAfee-GW-EditionBehavesLike.Win32.Virus.tt
FireEyeGeneric.mg.2c10bf9448808066
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
VBA32BScope.Trojan.Convagent
MalwarebytesMalware.AI.3712959942
TrendMicro-HouseCallTROJ_GEN.R002H0CA422
RisingVirus.Expiro!8.375 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Expiro.NDO!tr
AVGWin32:FileInfector-C [Heur]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.3712959942?

Malware.AI.3712959942 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment