Malware

About “Malware.AI.3763619525” infection

Malware Removal

The Malware.AI.3763619525 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3763619525 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3763619525?


File Info:

name: 5926C46C53DE8835D75B.mlw
path: /opt/CAPEv2/storage/binaries/353aca43ed897b6bb1fd85a5b390a4e3788f85862fac9281e4e10cfc4ebe49ba
crc32: 61362B3C
md5: 5926c46c53de8835d75b706bbe834d91
sha1: 094859933d765f13e8a8d9bf9692753516617a14
sha256: 353aca43ed897b6bb1fd85a5b390a4e3788f85862fac9281e4e10cfc4ebe49ba
sha512: 586f8b12ebc0f58be2a44dc4acc1c8f2f89d0994345f1540b02af48aee002cbbe7062bb04a8a205fcfdcc8c08e2d476c511250cba9401ec73ef7d7f2c6caf3d5
ssdeep: 49152:DqeNVz3PRDjRz5r8Nvh/20G6ZXphFNrx27Y4hvgqjO6d2kiO:+ER3PRx5r8Nvh7vZXRNdk/7ZokD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159E5E13FB268A43ED46B573249B392705A7B7E61A91A8C2F03F0650DCF365601E3F616
sha3_384: c6b8dd03eb8f5fda3a7f3d5eae3290efcf863bad82f7aaa0a03ceba1b666367280225283b34611b3860e0c6362f2c83b
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-05-21 05:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: 武汉旭大科技有限公司
FileDescription: 山海货币换算 安装程序
FileVersion: 1.0.1.25
LegalCopyright: 版权所有 ©2021 武汉旭大科技有限公司
OriginalFileName:
ProductName: 山海货币换算
ProductVersion: 1.0.1.25
Translation: 0x0000 0x04b0

Malware.AI.3763619525 also known as:

LionicAdware.Win32.Burden.2!c
MicroWorld-eScanAdware.GenericKD.38068158
FireEyeAdware.GenericKD.38068158
ALYacAdware.GenericKD.38068158
CylanceUnsafe
SangforTrojan.Win32.Agent.ACAV
K7AntiVirusTrojan ( 0056ef6d1 )
AlibabaAdWare:Win32/Burden.1dc8ea87
K7GWTrojan ( 0056ef6d1 )
CyrenW32/Trojan.YFTK-8413
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.ACAV
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Burden.gen
BitDefenderAdware.GenericKD.38068158
AvastWin32:MalwareX-gen [Trj]
Ad-AwareAdware.GenericKD.38068158
EmsisoftAdware.GenericKD.38068158 (B)
F-SecureHeuristic.HEUR/AGEN.1211299
DrWebTrojan.Siggen13.53465
TrendMicroTROJ_GEN.R002C0DA622
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA AJ (PUA)
IkarusTrojan.Win32.Agent
AviraHEUR/AGEN.1211299
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataAdware.GenericKD.38068158
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R446554
McAfeeArtemis!5926C46C53DE
MAXmalware (ai score=67)
VBA32Trojan.Sabsik.TE
MalwarebytesMalware.AI.3763619525
TrendMicro-HouseCallTROJ_GEN.R002C0DA622
RisingAdware.Agent!1.D701 (CLASSIC)
YandexPUA.Burden!aTmEBhe+38k
MaxSecureTrojan.Malware.138676707.susgen
BitDefenderThetaGen:NN.ZexaE.34606.fx3@auYaQOkb
AVGWin32:MalwareX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_70% (D)

How to remove Malware.AI.3763619525?

Malware.AI.3763619525 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment