Malware

Malware.AI.3771030432 removal tips

Malware Removal

The Malware.AI.3771030432 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3771030432 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Modifies Image File Execution Options, indicative of process injection or persistence
  • Created a service that was not started

How to determine Malware.AI.3771030432?


File Info:

name: 7C1AD3D4068C140ECDC7.mlw
path: /opt/CAPEv2/storage/binaries/f2092a4fc514f4524423bf4664c450d2876161cc9c4bd0a5d4b23bd8b267aaaa
crc32: C543A946
md5: 7c1ad3d4068c140ecdc712bef7af80dc
sha1: 21b3d88771c8f052d9a5febe7058ab12d801ad55
sha256: f2092a4fc514f4524423bf4664c450d2876161cc9c4bd0a5d4b23bd8b267aaaa
sha512: b6353b01287e0fe9e3f6c22e4a87f74497ffe8a0e9454f1d545d8429ee01d6451a0ace81db428ea8a2c2c7baeb54dc873b3d7a34f5a917ceaa54a1ab1ff8f60e
ssdeep: 24576:/fL4mfoRFPOl8oHaNjaNxnYw527vYCTjt5bkKa2gwhchR796UrFzRg/Rb:3zfoRFP28IYGNpYi+vLTjiJwstAmzWb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165450101E5D74032E7B32A33D9F4B6B9597DBC204737896F2388EA690E34D11AE25732
sha3_384: 5969b958ff2a4a398c88bca5e69e4b7b39a5d87a5ee1384c17aa4215269a98bd88645554b48deb87fbba67c02349a565
ep_bytes: e86d020000e98efeffff558bec8b4508
timestamp: 2019-02-26 12:55:32

Version Info:

CompanyName: CRYPTOCOMPANY OU
FileDescription: CryptoTab Update Setup
FileVersion: 1.3.99.25
InternalName: CryptoTab Update Setup
LegalCopyright: Copyright 2018 CRYPTOCOMPANY OU
OriginalFilename: CryptoTabUpdateSetup.exe
ProductName: CryptoTab Update
ProductVersion: 1.3.99.25
LanguageId: en
PrivateBuild:
Translation: 0x0409 0x04b0

Malware.AI.3771030432 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.36764673
CAT-QuickHealTrojan.Agent
McAfeeGenericRXHR-GW!7C1AD3D4068C
CylanceUnsafe
ZillyaAdware.CryptoTab.Win32.2
SangforTrojan.Win32.GenericKD.36764673
K7AntiVirusAdware ( 0057a4b41 )
K7GWAdware ( 0057a4b41 )
CyrenW32/Trojan.BMRL-3431
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/CryptoTab.A potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Dropper.Reline-9916519-0
BitDefenderTrojan.GenericKD.36764673
NANO-AntivirusTrojan.Win32.CryptoTab.iuhknm
SophosGeneric PUA CB (PUA)
DrWebTrojan.MulDrop16.45014
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXHR-GW!7C1AD3D4068C
EmsisoftTrojan.GenericKD.36764673 (B)
GDataTrojan.GenericKD.36764673
MaxSecureTrojan.Malware.74350272.susgen
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3771030432
TrendMicro-HouseCallTROJ_GEN.R002H0CL421
YandexRiskware.Agent!ZylfcmmGL0E
FortinetRiskware/CryptoTab

How to remove Malware.AI.3771030432?

Malware.AI.3771030432 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment