Malware

Malware.AI.3762976481 (file analysis)

Malware Removal

The Malware.AI.3762976481 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3762976481 virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3762976481?


File Info:

name: E478E45B07EDC84FA265.mlw
path: /opt/CAPEv2/storage/binaries/2352f5ca90d5f18731e1229ef2ef46ef595f514713349392da4f3a767e9d149d
crc32: ADC16C7A
md5: e478e45b07edc84fa265355d95e381cf
sha1: 225f6a741687783245d982bee207ba1e5742192e
sha256: 2352f5ca90d5f18731e1229ef2ef46ef595f514713349392da4f3a767e9d149d
sha512: d83ec88ec271b4b9fdeb9cc56d61c69afaae072829da8bbc30c15b3b400c7432a213f49c1620aa8d516738e7885e4792bbc74dba5d5ffe5a6bea7e9b6422e0e3
ssdeep: 3072:gjMDTfo15Y7CtI60aAc0wglz03vk4AnSOcnBHKcJpPmHOIU2Q66CnkSiQqlCEqEg:PTfo7YGuy0wWtnSOcxU6f7Cdi7oEqEg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153448D47BB84991FD0026372D5D94DB2B8FD1A509EB041273656C76EBB2F2ECE123B12
sha3_384: 0902db0e3fcf7bb13196f6230eccc167076a83c4f4db24922b3cff3d88588f5de9b4ccfa192f5b556545aa0cbc892234
ep_bytes: e9550000005a565750515389d3e84801
timestamp: 2106-02-07 06:28:15

Version Info:

0: [No Data]

Malware.AI.3762976481 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.GJIRTFMWXh6g.97B72F43
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.dh
McAfeeW32/Polybot.gen!irc
MalwarebytesMalware.AI.3762976481
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00553f0b1 )
K7GWTrojan ( 00553f0b1 )
Cybereasonmalicious.416877
VirITI-WORM.Mytob.BX
SymantecW32.Gaobot.gen!poly
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agobot.NAX
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Worm.Mytob-203
KasperskyBackdoor.Win32.Agobot.gen
BitDefenderGeneric.Malware.GJIRTFMWXh6g.97B72F43
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:HBPECrypt-A [Wrm]
TencentBackdoor.Win32.Agobot.za
EmsisoftGeneric.Malware.GJIRTFMWXh6g.97B72F43 (B)
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebWin32.HLLW.Agobot
VIPREGeneric.Malware.GJIRTFMWXh6g.97B72F43
TrendMicroWORM_AGOBOT.GEN
SophosMal/Behav-016
IkarusBackdoor.Win32.Agobot
GDataGeneric.Malware.GJIRTFMWXh6g.97B72F43
JiangminBackdoor/Agobot.hr
WebrootW32.Trojan.Worm-Mytob
VaristW32/Rbot.P.gen!Eldorado
AviraBDS/Backdoor.Gen
Antiy-AVLWorm/Win32.Agobot.a
Kingsoftmalware.kb.a.1000
XcitiumBackdoor.Win32.Agobot.hn0@1d9dgj
ArcabitGeneric.Malware.GJIRTFMWXh6g.97B72F43
ViRobotWorm.Win32.Agobot.gen
ZoneAlarmBackdoor.Win32.Agobot.gen
MicrosoftWorm:Win32/Gaobot
GoogleDetected
AhnLab-V3Win32/AgoBot.worm.Unknown
BitDefenderThetaAI:Packer.BE73A9CA1F
ALYacGeneric.Malware.GJIRTFMWXh6g.97B72F43
TACHYONBackdoor/W32.Agobot.266240.B
VBA32BScope.Backdoor.Agobot
Cylanceunsafe
PandaMalicious Packer
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallWORM_AGOBOT.GEN
RisingWorm.Mytob.hf (CLASSIC)
YandexWorm.Agobot.Wonk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AgoBot.fam!worm
AVGWin32:HBPECrypt-A [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3762976481?

Malware.AI.3762976481 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment