Malware

Malware.AI.3760708982 removal guide

Malware Removal

The Malware.AI.3760708982 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3760708982 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.3760708982?


File Info:

name: 6AD8F0FEADF6F114D13E.mlw
path: /opt/CAPEv2/storage/binaries/230321acb2bd40d6e19e34fb092c61ff3a11abd0cc878cbc67ddf7a59387d689
crc32: A31EE82B
md5: 6ad8f0feadf6f114d13edae2549f287b
sha1: b3083bf60a5262715b8d7359e102870d3569ebb2
sha256: 230321acb2bd40d6e19e34fb092c61ff3a11abd0cc878cbc67ddf7a59387d689
sha512: dffa1b933f9acf2584149f49a68011c2b562e9cb74c2bd5604d1c1a1be88ff8243e415d8e2aef0358f3580c4ff67049bc0109087e0aefcfeb3138801513c2aae
ssdeep: 12288:p/ke9m6SMFLryyXz88fF6HznUg71r24HMHLi8:prhF4FUg71r2gC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168C4DF22B7F4C4B1E5B211B74983C719BBF2BD144939CA1367E11F1EEEB86419A0A353
sha3_384: 4eea53eeede171a33e17c266913ad3237d64faf069159ecbddb09495ae61eb74da475fe1f42437c2a2b1597146659c42
ep_bytes: e85a6d0000e916feffff3b0dc8ca4300
timestamp: 2018-06-27 09:39:06

Version Info:

FileVersion: 4.7.50.5
LegalTrademarks: Copyright 2015 SpaceX
FileDescription: Dlc Daemon Notification Operating Ceilings
CompanyName: SpaceX
Comments: Dlc Daemon Notification Operating Ceilings
OriginalFilename: Cubes
LegalCopyright: Copyright 2015 SpaceX
PrivateBuild: 4.7.50.5
ProductName: Cubes
InternalName: Cubes
ProductVersion: 4.7.50.5
Translation: 0x0409 0x04b0

Malware.AI.3760708982 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.6ad8f0feadf6f114
McAfeeArtemis!6AD8F0FEADF6
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.52460
AlibabaBackdoor:Win32/Androm.2b54a77f
Cybereasonmalicious.60a526
BitDefenderThetaGen:NN.ZexaF.34294.Jq0@aiEnWmei
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GIFZ
TrendMicro-HouseCallTROJ_GEN.R002H0CKM21
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.qbpj
NANO-AntivirusTrojan.Win32.Androm.feqonn
AvastWin32:Trojan-gen
RisingTrojan.Generic@ML.98 (RDML:sStvSKa7VgeiS8QTidviiQ)
SophosMal/Generic-S
ComodoMalware@#njbjgv7d2l42
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Downloader.hc
IkarusTrojan.Win32.Crypt
JiangminBackdoor.Androm.aael
AviraHEUR/AGEN.1109237
Antiy-AVLTrojan[Backdoor]/Win32.Androm
MicrosoftTrojan:Win32/Occamy.C23
AhnLab-V3Malware/Win32.Generic.C3536919
VBA32BScope.Backdoor.Androm
MalwarebytesMalware.AI.3760708982
APEXMalicious
TencentWin32.Backdoor.Androm.Wskm
YandexBackdoor.Androm!hdGo/sZrEY4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GKNI!tr.ransom
AVGWin32:Trojan-gen
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.3760708982?

Malware.AI.3760708982 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment