Malware

What is “Malware.AI.3775521545”?

Malware Removal

The Malware.AI.3775521545 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3775521545 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Malware.AI.3775521545?


File Info:

name: C646AAF3CCFF13DAE5E5.mlw
path: /opt/CAPEv2/storage/binaries/779ff2db29e4462ff236719061f69f07ff05bbc6fdb8f7914e8c6274f8191963
crc32: 0925FF87
md5: c646aaf3ccff13dae5e54071fc3c446b
sha1: 9ec29b1aa6dd461b944af125cde7474271d1a5b0
sha256: 779ff2db29e4462ff236719061f69f07ff05bbc6fdb8f7914e8c6274f8191963
sha512: 02aff49b1ca02a284da123522d6f6ab03ca390b914ffa625d05881c7aa6d24468cc0cf561938b4f9122df0c5728b8659f8298646421465ccb5705f70dfc23791
ssdeep: 3072:BR0aAAFbuGycQxU0PMDAwjDnUMcypdfbGcSTaNE7gld50n76bXiO:JFbuGzQEzUsbaq07pO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E049CE2C267A1CCF342037DBC04C7525C969CAAA2D197C174B12F8D87A652F4E5BE1E
sha3_384: d36b378713bfe8f46c7a4954b8e8c052a8c278e39c9a90a3025deabbc62401819f3a6837f35804183ade7fb0be05bbb0
ep_bytes: 6a40680010000068a08601006a00ff15
timestamp: 2012-09-05 20:26:28

Version Info:

0: [No Data]

Malware.AI.3775521545 also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.AutoRun.o!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner3.499
MicroWorld-eScanGen:Variant.Downloader.126
FireEyeGeneric.mg.c646aaf3ccff13da
McAfeeGenericRXAA-AA!C646AAF3CCFF
CylanceUnsafe
K7AntiVirusEmailWorm ( 0052ca6a1 )
AlibabaWorm:Win32/AutoRun.20909150
K7GWEmailWorm ( 0052ca6a1 )
Cybereasonmalicious.3ccff1
ArcabitTrojan.Downloader.126
BitDefenderThetaAI:Packer.10D9AA541E
CyrenW32/Kryptik.AJG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.Agent.AFG
TrendMicro-HouseCallTROJ_GEN.R002C0RKT21
Paloaltogeneric.ml
KasperskyHEUR:Worm.Win32.AutoRun.pef
BitDefenderGen:Variant.Downloader.126
TencentWin32.Worm.Autorun.Sxec
Ad-AwareGen:Variant.Downloader.126
EmsisoftGen:Variant.Downloader.126 (B)
ComodoEmailWorm.Win32.AutoRun.KA@719dtc
TrendMicroTROJ_GEN.R002C0RKT21
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosML/PE-A + Troj/Agent-BCGS
IkarusVirus.Win32.Heur
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASBOL.C6BE
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Downloader.126
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R295338
Acronissuspicious
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3775521545
PandaTrj/Genetic.gen
APEXMalicious
RisingWorm.Autorun!1.AFBF (CLASSIC)
YandexTrojan.GenAsa!6D0EeHKQIts
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.AFG!tr
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3775521545?

Malware.AI.3775521545 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment