Malware

Malware.AI.3718792597 removal

Malware Removal

The Malware.AI.3718792597 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3718792597 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Connects to crypto currency mining pool
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • CAPE detected the CoinMiner02 malware family
  • A cryptomining command was executed

Related domains:

xmr.pool.minergate.com
wpad.local-net

How to determine Malware.AI.3718792597?


File Info:

name: C6D9E84BE3E3D91D3381.mlw
path: /opt/CAPEv2/storage/binaries/c190c182f274063cbd3fc80f71175c7a37ae72d22bf4f93199f59cb4f347e78f
crc32: F0E0B56C
md5: c6d9e84be3e3d91d3381123d3b81c28a
sha1: 82c47ce75ec7ba1c535e0610112255225fd68c89
sha256: c190c182f274063cbd3fc80f71175c7a37ae72d22bf4f93199f59cb4f347e78f
sha512: bfd89b56f81fa93fd042407ae9e63045d4e557b362b6e0be84ebe6a84a3625da981d2fe27dea397b81cf8091bb94b403443997b465c3612048c98a5368330b40
ssdeep: 49152:kx7ITMa5/892blc+uPIjzOjfsdKdvhWPGS/EKPXOjN5fQJ:k6TMa5/8Yc9mi0QWPGS/1fUN5O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CC52301BAC18A71C5226D33AB255B5169BD7C110F39862FF3DC2A6DC7351A0A239BF7
sha3_384: 4a7367f56896aa05b11268ffabcc606ae259825d50836543e7c8cdce061c1e50cb4811c5c225617e8ec1cce0612000b0
ep_bytes: e8ce040000e98efeffff3b0d68d64300
timestamp: 2019-09-26 08:33:43

Version Info:

0: [No Data]

Malware.AI.3718792597 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Miner.4!c
MicroWorld-eScanApplication.BitCoinMiner.RD
FireEyeGeneric.mg.c6d9e84be3e3d91d
ALYacGen:Variant.Application.Miner.2
CylanceUnsafe
SangforCoinMiner.Script.Miner.gen
AlibabaTrojanDownloader:Win64/Miners.da433740
Cybereasonmalicious.be3e3d
CyrenW32/Application.ZTMR-5562
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.PO potentially unwanted
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Miner
BitDefenderApplication.BitCoinMiner.RD
NANO-AntivirusRiskware.Win32.BitCoinMiner.hfdtwy
AvastWin32:Miner-DM [Trj]
RisingHackTool.XMRMiner!1.C2EC (CLASSIC:AE1pALMOfnbmuJ11LmaDzw)
SophosGeneric PUA IC (PUA)
ComodoMalware@#1o1irydxe94j9
DrWebTrojan.MulDrop7.6452
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_DYNAMER_FI080299.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftApplication.BitCoinMiner.RD (B)
SentinelOneStatic AI – Malicious SFX
WebrootW32.Gen.BT
MAXmalware (ai score=77)
Antiy-AVLTrojan/Generic.ASMalwS.11DBAC0
MicrosoftRansom:Win32/Blocker
GDataGen:Variant.Application.Miner.2
CynetMalicious (score: 100)
McAfeeArtemis!C6D9E84BE3E3
VBA32Hoax.Blocker
MalwarebytesMalware.AI.3718792597
IkarusPUA.CoinMiner
FortinetRiskware/Script
AVGWin32:Miner-DM [Trj]
PandaTrj/CI.A
MaxSecureTrojan.Malware.73756954.susgen

How to remove Malware.AI.3718792597?

Malware.AI.3718792597 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment