Malware

Malware.AI.3725969139 information

Malware Removal

The Malware.AI.3725969139 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3725969139 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.3725969139?


File Info:

name: 6C4CD6BED9B2495812D3.mlw
path: /opt/CAPEv2/storage/binaries/5731321b49c25cf22c1d1848b72458b25c96974fd58b47bc546bf8a583fb8cbe
crc32: 6B14EEB1
md5: 6c4cd6bed9b2495812d3f2ec83c9ec8d
sha1: 98fd48d6dc0fc07a5089021c246d2a5ebe6746bf
sha256: 5731321b49c25cf22c1d1848b72458b25c96974fd58b47bc546bf8a583fb8cbe
sha512: dd20fe1daeddb8c63b0ee8b7a1e1ede79de22f9500a054550adfc355dcb5f8d25c03d8941eb2da324ab7b580e082416a15ad14ca4c499bef34494a4f09d3f620
ssdeep: 393216:hkSl2LWPAOPY9k6P0RT48fh91wT5N0dPHhndQHR6QLkjx:3PLM01LD1U5NOAHR67
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150F6339CBCAC8728C8F84CB54E67A6699A77A4D2D872A71CF810550F03534C96FBB473
sha3_384: f4ba61ab22d0b37ac11c9419875de1bbc40a076daee5f0ed58d0cdf463d5be534ecbb2298ba5882d876c4a0a62f0e4ca
ep_bytes: ff250020400000000000000000000000
timestamp: 2066-06-21 01:50:22

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Windows Sürücü Yapısı
FileVersion: 1.0.0.0
InternalName: Windows Sürücü Yapısı.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: Windows Sürücü Yapısı.exe
ProductName: Windows Sürücü Yapısı
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3725969139 also known as:

BkavW32.Common.BFF498A1
LionicTrojan.Win32.Bobik.l!c
MicroWorld-eScanGen:Variant.Tedy.511608
FireEyeGen:Variant.Tedy.511608
SkyhighArtemis!Trojan
McAfeeArtemis!6C4CD6BED9B2
Cylanceunsafe
SangforSpyware.Msil.Bobik.Vtyt
AlibabaTrojanSpy:MSIL/Bobik.e6d2ab3e
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Small.IL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.Bobik.gen
BitDefenderGen:Variant.Tedy.511608
AvastWin32:SpywareX-gen [Trj]
TencentMsil.Trojan-Spy.Bobik.Xwhl
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Bobik.jkrgv
VIPREGen:Variant.Tedy.511608
TrendMicroTROJ_GEN.R011C0XA524
EmsisoftGen:Variant.Tedy.511608 (B)
IkarusTrojan.SPY.Bobik
GDataGen:Variant.Tedy.511608
GoogleDetected
AviraTR/Spy.Bobik.jkrgv
Antiy-AVLTrojan[Spy]/MSIL.Bobik
ArcabitTrojan.Tedy.D7CE78
ZoneAlarmHEUR:Trojan-Spy.MSIL.Bobik.gen
MicrosoftProgram:Win32/Wacapew.C!ml
VaristW32/ABRisk.UOAI-3865
ALYacGen:Variant.Tedy.511608
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3725969139
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R011C0XA524
RisingSpyware.Bobik!8.108FF (CLOUD)
MaxSecureTrojan.Malware.216125030.susgen
FortinetPossibleThreat
AVGWin32:SpywareX-gen [Trj]
Cybereasonmalicious.6dc0fc
DeepInstinctMALICIOUS

How to remove Malware.AI.3725969139?

Malware.AI.3725969139 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment