Malware

Malware.AI.3757035125 removal tips

Malware Removal

The Malware.AI.3757035125 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3757035125 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Malware.AI.3757035125?


File Info:

name: BD4825F2E71378CF240D.mlw
path: /opt/CAPEv2/storage/binaries/fff6d95388990c91c632889e46102355b66adfb1cadd769dedfaf334b30f8a78
crc32: BC8E7711
md5: bd4825f2e71378cf240d04070e806a15
sha1: f51dae32fc814537cef648642aa6cff5b999b172
sha256: fff6d95388990c91c632889e46102355b66adfb1cadd769dedfaf334b30f8a78
sha512: ca5a498f9f4578bce2bc6627c209d9ac4264de50b0e0ba608c6582005c1b11b69267fdf9e0142160a5281a0f7ea22bfab4df142a060cedcec468a780f6ce62dc
ssdeep: 6144:bwZif2SpG9pGjqty0RnkdOk4SH5NJ1xtCTbSO40hkIaEM:29SpgGgy0RXkPXxtC34ukr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14994F0496198D55BF2DA363D6FA2C9BA4374CCCC6A4246233BF87F9B35FC2472104262
sha3_384: b43963cef51d4c5e71af21dfa0d74e1f883e1e82707c983af24f93d5a78688d5a690c147e4141eebe3b3d92fae7046c6
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Malware.AI.3757035125 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.38118
MicroWorld-eScanTrojan.GenericKD.38766012
FireEyeTrojan.GenericKD.38766012
CAT-QuickHealTrojan.Sabsik
ALYacTrojan.GenericKD.38766012
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058d8fe1 )
AlibabaTrojanSpy:Win32/Formbook.c9d93b56
K7GWTrojan ( 0058d8fe1 )
Cybereasonmalicious.2e7137
BitDefenderThetaGen:NN.ZedlaF.34232.bq4@ai63ANii
VirITTrojan.Win32.PSWStealer.DFH
CyrenW32/Injector.ATR.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQZU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.38766012
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan-spy.Noon.Pgwm
Ad-AwareTrojan.GenericKD.38766012
EmsisoftTrojan.GenericKD.38766012 (B)
ComodoMalware@#19aiuxlxsk1xt
TrendMicroTROJ_GEN.R06FC0TAR22
McAfee-GW-EditionNSIS/ObfusInjector.h
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.38766012
AviraTR/AD.Swotter.olerc
GridinsoftRansom.Win32.Sabsik.sa
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Formbook!MTB
CynetMalicious (score: 100)
McAfeeArtemis!BD4825F2E713
MAXmalware (ai score=81)
VBA32Trojan.Formbook
MalwarebytesMalware.AI.3757035125
TrendMicro-HouseCallTROJ_GEN.R06FC0TAR22
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusTrojan.NSIS.Agent
FortinetW32/EQZU!tr
AVGWin32:InjectorX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3757035125?

Malware.AI.3757035125 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment