Malware

Malware.AI.3769088385 (file analysis)

Malware Removal

The Malware.AI.3769088385 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3769088385 virus can do?

  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.3769088385?


File Info:

name: B5C68B02EC663842B1F0.mlw
path: /opt/CAPEv2/storage/binaries/983e5e5645a8cd895d45e409151d763c1336150872d733732b5bc39fe43f0758
crc32: 88C20D2F
md5: b5c68b02ec663842b1f03656897d9d3e
sha1: 67c2e7f14e2360aa9596e8fb98617994356018f8
sha256: 983e5e5645a8cd895d45e409151d763c1336150872d733732b5bc39fe43f0758
sha512: 3eceb9c51f380e5163ba3e220f0abbba0ff1c423365f4989c5fbf4086c352f771da5a88ae4281438b3c52289f425c105d273f8b073c23f94d5ea41105be3a0ea
ssdeep: 3072:SVb3gm7sNBNLrWqGFNfB2smmauewHCUMkagby23hLBF8jDbtqWMpALJ:SVb3HiNLrgNQlmAwHaNghNI/Ma
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161B4B61B7BDECE14D2B2D4FCD6167B84869B6E13165ED522D1E23932C2AFB41A9070C3
sha3_384: 0141991d456ca79bdb34db25d0022f08733d9f9cb10b9b8315e0844b4d3188cc694759ae4ba595cb37910750ffae5675
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-09-30 16:12:38

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Client
FileVersion: 1.0.10.0
InternalName: Client.exe
LegalCopyright: Copyright © 2021 五块半
LegalTrademarks:
OriginalFilename: Client.exe
ProductName: Client
ProductVersion: 1.0.10.0
Assembly Version: 1.0.10.0

Malware.AI.3769088385 also known as:

BkavW32.Common.A30B3112
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.68035459
SkyhighBehavesLike.Win32.Generic.hh
McAfeeArtemis!B5C68B02EC66
Cylanceunsafe
SangforTrojan.Win32.Agent.V52p
Cybereasonmalicious.14e236
ArcabitTrojan.Generic.D40E2383
BitDefenderThetaGen:NN.ZemsilF.36680.Gm0@a0ngfT
VirITTrojan.Win32.MSIL_Heur.A
Elasticmalicious (high confidence)
APEXMalicious
BitDefenderTrojan.GenericKD.68035459
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.68035459 (B)
VIPRETrojan.GenericKD.68035459
SophosGeneric ML PUA (PUA)
IkarusTrojan.Crypt
GoogleDetected
VaristW32/ABRisk.YXRL-1174
Antiy-AVLTrojan/Win32.SGeneric
Kingsoftmalware.kb.c.980
GDataTrojan.GenericKD.68035459
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.68035459
MalwarebytesMalware.AI.3769088385
PandaTrj/Agent.AY
TrendMicro-HouseCallTROJ_GEN.R002H09GB23
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:1ho8J64HQC9GocjB6nPeag)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.218488414.susgen
FortinetRiskware/Application
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.3769088385?

Malware.AI.3769088385 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment