Malware

Malware.AI.3756071719 (file analysis)

Malware Removal

The Malware.AI.3756071719 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3756071719 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3756071719?


File Info:

name: 5DF4A1824AE8538313C4.mlw
path: /opt/CAPEv2/storage/binaries/531837b9797d831fd310f64626c003eb12d4edd9007989938725ae1b713a6be4
crc32: 00D24569
md5: 5df4a1824ae8538313c4681381eaca61
sha1: 708a4099a54bee54bb69a38e0a09fccc67c2790d
sha256: 531837b9797d831fd310f64626c003eb12d4edd9007989938725ae1b713a6be4
sha512: 40d09d1d29579a3eb5843999b55b581552a04e6ab9187b18f2515d71bfdd6d523c4c9e3e1c2c6c3474bf809b06d2219010f774b491eb6a02cb15f549b0be5848
ssdeep: 1536:+VNEfxvOYM9zqqYyIIMJCZ7iqHWWzpatef6O0+DZFT+eP6TfXkcOalSJWYwTLy:UE9lwdYyIIMJCZ7idewtUY+fT+eP2fsf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1730206DE24EA96E0CBA8380F758352157FFC661A2D981F3B9033AB7E31D830E05617
sha3_384: ee219b1cb4d8872e3e83461742b92a8ae0db150f1905c8a6b04442f912fc2b017c1e2cda66c350966ab69fee7be72cc0
ep_bytes: b82c6744005064ff3500000000648925
timestamp: 2011-11-16 01:00:22

Version Info:

Comments:
CompanyName: Auto Debug System
FileDescription: Kill Process Module
FileVersion: 1, 1, 1, 10
InternalName: KillProcess
LegalCopyright: Copyright 2003-2007 Auto Debug System
LegalTrademarks:
OriginalFilename: KillProcess.exe
PrivateBuild:
ProductName: KillProcess Module
ProductVersion: 1, 1, 1, 10
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.3756071719 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Nuev.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.5df4a1824ae85383
McAfeeGenericRXBG-YG!5DF4A1824AE8
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Buzus.5be33df4
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9a54be
BitDefenderThetaGen:NN.ZexaF.34796.ei2@a0Ay5Kii
CyrenW32/Buzus.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
BaiduWin32.Worm.VB.mt
APEXMalicious
ClamAVWin.Malware.Buzus-6998813-0
KasperskyTrojan.Win32.Nuev.vhu
BitDefenderTrojan.GenericKDZ.83028
NANO-AntivirusTrojan.Win32.VBKrypt.wpqdj
SUPERAntiSpywareTrojan.Agent/Gen-KProc
MicroWorld-eScanTrojan.GenericKDZ.83028
AvastWin32:VB-ZTY [Trj]
TencentMalware.Win32.Gencirc.10b6dc8a
Ad-AwareTrojan.GenericKDZ.83028
SophosML/PE-A + Mal/Agent-AFV
ComodoTrojWare.Win32.TrojanDropper.Agent.OFF@4lics1
F-SecureTrojan.TR/Offend.6991746
DrWebTrojan.Packed.22174
VIPRETrojan.GenericKDZ.83028
McAfee-GW-EditionGenericRXBG-YG!5DF4A1824AE8
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.83028 (B)
IkarusTrojan.SuspectCRC
GDataTrojan.GenericKDZ.83028
JiangminTrojan/Buzus.bcjz
AviraTR/Offend.6991746
MAXmalware (ai score=94)
Antiy-AVLTrojan/Win32.Buzus
ArcabitTrojan.Generic.D14454
ZoneAlarmTrojan.Win32.Nuev.vhu
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R10911
ALYacTrojan.GenericKDZ.83028
VBA32Trojan.Nuev
MalwarebytesMalware.AI.3756071719
TrendMicro-HouseCallTROJ_AUTORUN_00000cc.TOMA
RisingWorm.Autorun!8.50 (TFE:3:Rjz7lUu8Y9E)
YandexTrojan.Buzus!jZRK4bS/xog
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.3373567.susgen
FortinetW32/AutoRun_VB.APM
AVGWin32:VB-ZTY [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.3756071719?

Malware.AI.3756071719 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment