Malware

Malware.AI.3768465349 removal instruction

Malware Removal

The Malware.AI.3768465349 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3768465349 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.3768465349?


File Info:

name: 77BDAF51505AA1A4941A.mlw
path: /opt/CAPEv2/storage/binaries/c88f551c9f58239743dd5966394dded7c470e473a54cdd8055fc38ba799ef504
crc32: A9A95E7A
md5: 77bdaf51505aa1a4941a19ca8f2f567e
sha1: 5b692160c980bfcbeb6ff81ad7a33e1dd7feadd5
sha256: c88f551c9f58239743dd5966394dded7c470e473a54cdd8055fc38ba799ef504
sha512: 70acdeb3fd0b53ae602cd603772122f34b6be25c2654953d25db27535d8100f9a931a5c606329409cecfdfeb3910c4e3c138f1024022d706d4698c0337db8291
ssdeep: 98304:vg5c3Jbri/+M2qn2lzhAZ7iv4AuTG4+ibkDV9P6Q:MUi/z5n2ld7uTG46DVNZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE06338265C502B3F9A65B79A13357A387823C0214E824D0B75D7FAFFD772908849BB7
sha3_384: 291f2c1ba86a9232fabcec41fabbe2e53cd40e9841026a8f2ee7c0d20308e2a367f6a3f5584296e37830940d9d5f3da2
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:19:59

Version Info:

CompanyName: KSCore Network Technology Co., Ltd
FileDescription: 文本查看程序
FileVersion: 1.0.1.352
LegalCopyright: Copyright (C) 2020 SimpleNotepad Inc. All rights reserved.
ProductName: SimpleNotepad
ProductVersion: 1.0.1.352
Translation: 0x0804 0x04b0

Malware.AI.3768465349 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Cjishu.2!c
MicroWorld-eScanAdware.GenericKD.48207919
FireEyeAdware.GenericKD.48207919
ALYacAdware.GenericKD.48207919
CylanceUnsafe
ZillyaAdware.Cjishu.Win32.226
SangforSuspicious.Win32.Zusy.412800
K7AntiVirusTrojan ( 0056e5201 )
AlibabaAdWare:Win32/Cjishu.3ceaf69c
K7GWTrojan ( 0056e5201 )
BitDefenderThetaGen:NN.ZexaF.34232.Gu0@amE@Bqcj
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
Kasperskynot-a-virus:UDS:AdWare.Win32.Cjishu.gen
BitDefenderAdware.GenericKD.48207919
RisingAdware.AdPop!1.B85F (CLASSIC)
Ad-AwareAdware.GenericKD.48207919
SophosGeneric PUA FL (PUA)
F-SecureAdware.ADWARE/Cjishu.xejgv
McAfee-GW-EditionBehavesLike.Win32.PUP.wc
EmsisoftAdware.GenericKD.48207919 (B)
Paloaltogeneric.ml
GDataAdware.GenericKD.48207919
AviraADWARE/Redcap.pxvjp
Antiy-AVLGrayWare[AdWare]/Win32.Cjishu
GridinsoftRansom.Win32.Wacatac.sa
ArcabitAdware.Generic.D2DF982F
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Cjishu.gen
MicrosoftProgram:Win32/Uwamson.A!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.C4405779
McAfeeArtemis!77BDAF51505A
MAXmalware (ai score=69)
VBA32BScope.TrojanDropper.Dycler
MalwarebytesMalware.AI.3768465349
TrendMicro-HouseCallTROJ_GEN.R03FH0CAQ22
TencentWin32.Trojan.Multiple.Ajmb
MaxSecureTrojan.Malware.110334979.susgen
AVGWin32:TrojanX-gen [Trj]
PandaTrj/CI.A

How to remove Malware.AI.3768465349?

Malware.AI.3768465349 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment