Malware

Malware.AI.3718060728 removal guide

Malware Removal

The Malware.AI.3718060728 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3718060728 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Malware.AI.3718060728?


File Info:

name: 88C51430686D754A5E15.mlw
path: /opt/CAPEv2/storage/binaries/f5ccda4b3308aba63f9a89455486e58cc9caecd4e09d906009414bc470523050
crc32: 13DEFFFE
md5: 88c51430686d754a5e154e0394723c70
sha1: 37f629e6fe369c9f5ef1b6005b3fe92502d3f350
sha256: f5ccda4b3308aba63f9a89455486e58cc9caecd4e09d906009414bc470523050
sha512: 4235d8bf99abec6034604efbd9078ac18ab18f622b5a7721b841cc9f59c2d7da17bace2d5828f1e9a0f3c9daf1878506417e1eb8a7c7728bc1e511c918394338
ssdeep: 98304:xFEWSg97uwdMUIgWW4VznveSoOQzXgVhlbKNSkrbZGyPHDpyDhfC9kaM0:xFEWSE7FfeW4k1LymnZGyPHkDhfMq0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C33623734235054AE1F4CD3D8A37BEA531F60377CA81AC78B5BEAEC529168A1F213953
sha3_384: e8762fcbb169ec720f51cfcfc1ed5d231a89621e71f7b84d2e6a57df176e805df2c4caa3a4fea499c4c18ace60d2a716
ep_bytes: 68d1f01ab8e89cd1130081c706000000
timestamp: 2009-03-20 23:11:45

Version Info:

Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName: Apache Software Foundation
FileDescription: ApacheBench command line utility
FileVersion: 2.2.14
InternalName: ab.exe
LegalCopyright: Copyright 2009 The Apache Software Foundation.
OriginalFilename: ab.exe
ProductName: Apache HTTP Server
ProductVersion: 2.2.14
Translation: 0x0409 0x04b0

Malware.AI.3718060728 also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
FireEyeGeneric.mg.88c51430686d754a
CylanceUnsafe
VIPREGen:Variant.Ursu.94453
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.0686d7
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
BitDefenderGen:Variant.Ursu.94453
MicroWorld-eScanGen:Variant.Ursu.94453
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Variant.Ursu.94453
SophosMal/VMProtBad-A
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.94453 (B)
IkarusTrojan.Win32.Krypt
GDataGen:Variant.Ursu.94453
AviraHEUR/AGEN.1200370
MAXmalware (ai score=81)
ArcabitTrojan.Ursu.D170F5
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.Generic.R372623
Acronissuspicious
ALYacGen:Variant.Ursu.94453
VBA32BScope.Trojan.Vigorf
MalwarebytesMalware.AI.3718060728
RisingTrojan.Generic@AI.100 (RDML:qIr1p3+iw8EJdGhm+KE0hQ)
YandexTrojan.GenAsa!ZJARN1hYeBo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34786.@B0@aaBkokfi
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.3718060728?

Malware.AI.3718060728 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment