Malware

About “Malware.AI.3733923194” infection

Malware Removal

The Malware.AI.3733923194 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3733923194 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Malware.AI.3733923194?


File Info:

name: 07B1088A6FF3612DE448.mlw
path: /opt/CAPEv2/storage/binaries/da9b1fa4b5ed8237dd29ae8aa58ba56dd5a0b5f9958c1b287a51c4e4a4e9dcd4
crc32: C243F90D
md5: 07b1088a6ff3612de448058e6b9513e3
sha1: fd138bf63f1e972b07e4e15fc5a01a1fe36fc200
sha256: da9b1fa4b5ed8237dd29ae8aa58ba56dd5a0b5f9958c1b287a51c4e4a4e9dcd4
sha512: 191789342a4128350f48502669809337c980d4b8ee2987465858518c00ffcc47d2c90be429a759dd244f58062d8ff8b954268f779a9e6709cd32b4725a1ac684
ssdeep: 49152:iPvYT0UADcOHw8sjCjT4P0C7g+NkRhA/u8egNy5Vx5v/d5VpiQ3JefYqUJUbBIyZ:it3Jw8sjYA/urgcVxNnVohgqSUuc
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13C36D38EBCF8C75BC12398F0D75DD3C1293EDC8A8516E0D6ACE29E846EA16D6CC51349
sha3_384: a420c1332308850f0802607931e08ab60f97aec1614675b93d3975024b2ecaa0e55c3c30cf66174f330b4ffe5ad0befa
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-04-10 19:00:35

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: RiotPlus
FileVersion: 1.0.0.0
InternalName: Riot+.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Riot+.exe
ProductName: RiotPlus
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3733923194 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Razy.4!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
McAfeeArtemis!07B1088A6FF3
CylanceUnsafe
SangforTrojan.Win32.Save.a
Elasticmalicious (high confidence)
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-9877901-0
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Sodinokibi.rh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.07b1088a6ff3612d
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Fujacks
MicrosoftTrojan:Win32/Zpevdo.B
GDataWin32.Trojan.PSE.1650V88
MAXmalware (ai score=99)
MalwarebytesMalware.AI.3733923194
RisingTrojan.Generic@AI.95 (RDML:HlKec55vGFl72lIP63kHpQ)
IkarusTrojan.Win32
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34742.@x0@aCLYKDm
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.3733923194?

Malware.AI.3733923194 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment