Malware

Malware.AI.3733010012 (file analysis)

Malware Removal

The Malware.AI.3733010012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3733010012 virus can do?

  • Reads data out of its own binary image
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects the presence of Wine emulator via registry key
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3733010012?


File Info:

name: 8C7374876C0E25C89325.mlw
path: /opt/CAPEv2/storage/binaries/17049bb215fdd97a0357066e883445b6a78f62862e483e9453e72eb45cec547a
crc32: 88024E6A
md5: 8c7374876c0e25c89325d9c131e00957
sha1: d06b19638b0d1063bca870ef80bceca0bcc7d5e1
sha256: 17049bb215fdd97a0357066e883445b6a78f62862e483e9453e72eb45cec547a
sha512: d23c0b385ab55ac7fe93e0df0a24ba3b6fc295878cbc42d1d4b99fc5aaca2ca77bac2c2217b6a65878e6417600910a425901f45be496a1b6ae7b9bf9b06564e2
ssdeep: 49152:tyQHLtvSusr8YAQd7B1m3rIZB4ZCUbTDgi/LubGSfCjKrh/N6JepzTs:cctvAoRM7ff6ZCUNzuSCCjKrdNgepzTs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123C533D2C635AC7AD27A5476012F2EE205028C2AF1701B734F7B747D66324D3ABA6C67
sha3_384: e36508be84e4c2128682afcbce685acfc85b9a9eb60559e7ad3abde2f51d110af12f91343c4905f76ff64e1423e1fed8
ep_bytes: 60be15b078008dbeeb5fc7ffc787b0a9
timestamp: 2017-08-12 12:14:12

Version Info:

CompanyName: BitTorrent Inc.
FileDescription: µTorrent
FileVersion: 3.5.0.44040
InternalName: uTorrent.exe
OriginalFilename: uTorrent.exe
LegalCopyright: ©2016 BitTorrent, Inc. All Rights Reserved.
ProductName: µTorrent
ProductVersion: 3.5.0.44040
SpecialBuild: develop
Translation: 0x0409 0x04e4

Malware.AI.3733010012 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Utorrent.V7sf
CyrenW32/S-c95979d1!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/uTorrent.C potentially unwanted
APEXMalicious
ClamAVWin.Virus.Pioneer-6622830-0
DrWebAdware.OpenCandy.248
McAfee-GW-EditionBehavesLike.Win32.Sality.vc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Alien.ay
GoogleDetected
Antiy-AVLTrojan/Win32.Agent
CynetMalicious (score: 100)
MalwarebytesMalware.AI.3733010012
RisingMalware.Heuristic!ET#96% (C64:YzY0OhLZWRPwJnto)
YandexTrojan.GenAsa!2RMUL3CXDRc
IkarusTrojan-Downloader.Agent
FortinetRiskware/uTorrent.E6A1
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (W)

How to remove Malware.AI.3733010012?

Malware.AI.3733010012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment