Malware

Malware.AI.3740127450 removal instruction

Malware Removal

The Malware.AI.3740127450 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3740127450 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup

How to determine Malware.AI.3740127450?


File Info:

name: 41EC8F8D0BF0D50C85AE.mlw
path: /opt/CAPEv2/storage/binaries/1c4ba37bfe670943211d41422a625cff295c132d752d848a90453d1ce05cc38f
crc32: D124C756
md5: 41ec8f8d0bf0d50c85ae41ce7fab9dbe
sha1: 94c64d13b7209aa0a552cb18b55c03a308cd21fb
sha256: 1c4ba37bfe670943211d41422a625cff295c132d752d848a90453d1ce05cc38f
sha512: 1cb19bde719325632a510b4dc766b92dfb5ee20fdb28144efc6d62b52b113701508f995eb9e7478f313da0c6e6b0f13b6ec135965986bc83e4eb34bd44b389c2
ssdeep: 49152:/pDKHu5wxQ15guc1Kh0A0cGzO9HVwcfTXuFXBnTfTca7lFoLbZz:/puM15vF2A0cGzkmkXuFxn7plFoZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115B53303E79271FAD932FAB26F53A3359339B724EC06E525973844895F613918B36323
sha3_384: b2d53788d1b20657794708616bfc9f735abeee8be381f9b261fbbc58d34eb13205d957d97405b8ba0c8c14b26378e59e
ep_bytes: 558bec83c4b853565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.3740127450 also known as:

LionicRiskware.Win32.007SpySoft.1!c
MicroWorld-eScanBackdoor.Generic.175099
FireEyeBackdoor.Generic.175099
ALYacBackdoor.Generic.175099
CylanceUnsafe
SangforPUP.Win32.SpyAnyTime.B
K7AntiVirusUnwanted-Program ( 004d38111 )
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.d0bf0d
CyrenW32/Qqdragon.OPCN-8405
SymantecSpyware.ADH
ESET-NOD32a variant of Win32/Spy.007Spy potentially unsafe
Paloaltogeneric.ml
Kasperskynot-a-virus:Monitor.Win32.007SpySoft.342
BitDefenderBackdoor.Generic.175099
NANO-AntivirusRiskware.Win32.007SpySoft.bhqgw
AvastWin32:Keylog-S [Trj]
TencentTrojan.Win32.BitCoinMiner.la
SophosGeneric Reputation PUA (PUA)
ComodoMalware@#jodstpl8yjgu
DrWebTrojan.PWS.SpySoft.128
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
EmsisoftBackdoor.Generic.175099 (B)
JiangminMonitor.007SpySoft.p
WebrootSystem.Monitor.Ufp.007.Spy
AviraTR/Spy.Gen
MicrosoftPUA:Win32/Vigua.A
GDataBackdoor.Generic.175099
CynetMalicious (score: 99)
McAfeeArtemis!41EC8F8D0BF0
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3740127450
TrendMicro-HouseCallTROJ_GEN.R002H0CIT21
RisingTrojan.Spy.Agent.ary (CLASSIC)
FortinetRiskware/007SpySoft
AVGWin32:Keylog-S [Trj]
PandaApplication/007Spy

How to remove Malware.AI.3740127450?

Malware.AI.3740127450 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment