Malware

Malware.AI.3753642022 removal tips

Malware Removal

The Malware.AI.3753642022 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3753642022 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3753642022?


File Info:

name: 54808C09AA9453F046B6.mlw
path: /opt/CAPEv2/storage/binaries/4abd69d505bc148ded332662f6a6db2aef6133f3777f9adda68d121752877d06
crc32: 7B060AED
md5: 54808c09aa9453f046b65558c3b90252
sha1: c03f8a91f453c28a977ba39cb8dc256630404b4b
sha256: 4abd69d505bc148ded332662f6a6db2aef6133f3777f9adda68d121752877d06
sha512: a271bb2cf2f91ae31176e5844fd4adb7c38beac09ab93c0fd403bd305bf07bf6d5cd49e2b4e6acc635001ec6c61eb13b38e5fcb592930086b6c4aff85a65627a
ssdeep: 6144:c6SGAi+a1Bsf81KVv19XAzKd4hDfYlY1wtNesuNrGqRU:NRAiP1Bsf84tJdK2Yi7GEq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16564125BF105A4E1EB6DCF70219742F88366ED699CD758975900FF2E6C3C660EC1022E
sha3_384: d5347d6a29e697bde441a19b33e2c40e88ae919ba939e0bc84b82a4be5bd9136ab08be198effd44483176e557f1bea83
ep_bytes: 558bec6aff68a0394000687624400064
timestamp: 2017-05-04 07:59:44

Version Info:

CompanyName:
FileDescription: qunminghanzi Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: qunminghanzi
LegalCopyright: 版权所有 (C) 2017
LegalTrademarks:
OriginalFilename: qunminghanzi.EXE
ProductName: qunminghanzi 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Malware.AI.3753642022 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Glomaru.mDOx
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.KillMBR.A.BA61D42F
FireEyeGeneric.mg.54808c09aa9453f0
CAT-QuickHealTrojan.MauvaiseRI.S5247474
McAfeeGenericR-JVA!54808C09AA94
Cylanceunsafe
ZillyaTrojan.Magania.Win32.70520
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Zlob.180910
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9aa945
ArcabitDeepScan:Generic.KillMBR.A.BA61D42F
BaiduWin32.Trojan-Downloader.Agent.cw
VirITTrojan.Win32.PSWSteal.JBH
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Farfli.BGG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderDeepScan:Generic.KillMBR.A.BA61D42F
NANO-AntivirusTrojan.Win32.Magania.eraqjn
SUPERAntiSpywareTrojan.Agent/Gen-Magania
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b62112
EmsisoftDeepScan:Generic.KillMBR.A.BA61D42F (B)
F-SecureHeuristic.HEUR/AGEN.1346626
DrWebTrojan.DownLoader24.56477
VIPREDeepScan:Generic.KillMBR.A.BA61D42F
TrendMicroBKDR_ZEGOST.SM17
McAfee-GW-EditionGenericR-JVA!54808C09AA94
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.aydgj
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1346626
Antiy-AVLTrojan[GameThief]/Win32.Magania
XcitiumTrojWare.Win32.TrojanDownloader.Redosdru.FG@6j5x7c
MicrosoftTrojan:Win32/Farfli.AW!MTB
ZoneAlarmHEUR:Trojan.Win32.Staser.gen
GDataDeepScan:Generic.KillMBR.A.BA61D42F
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36350.su1@a4ldpqhb
ALYacDeepScan:Generic.KillMBR.A.BA61D42F
MAXmalware (ai score=89)
VBA32BScope.Trojan.Reconyc
MalwarebytesMalware.AI.3753642022
PandaTrj/Genetic.gen
ZonerTrojan.Win32.59037
TrendMicro-HouseCallBKDR_ZEGOST.SM17
RisingBackdoor.Zegost!8.177 (TFE:5:GOwLt6K7CAF)
IkarusTrojan.Win32.Farfli
FortinetW32/Farfli.BGG!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3753642022?

Malware.AI.3753642022 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment