Malware

What is “Malware.AI.3775543220”?

Malware Removal

The Malware.AI.3775543220 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3775543220 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executes the printer spooler process
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3775543220?


File Info:

name: 94E09D9751BF1AB4B16D.mlw
path: /opt/CAPEv2/storage/binaries/e70feb46cddd76b3543c2f0e1248389e35de2f8f22a83e403d632fd7cec97dd3
crc32: 0B7F7266
md5: 94e09d9751bf1ab4b16de44a23cadaf3
sha1: d622e0622f0043423ee037880234191878e5af3f
sha256: e70feb46cddd76b3543c2f0e1248389e35de2f8f22a83e403d632fd7cec97dd3
sha512: 883bf99321a99a03dcd849b7f653e305a067ba5aa58da72f7fbb10ac995729b78a3b1c7c0994350650d500e5a2f1ed2838796b574f5260c05841b2a0561ee575
ssdeep: 3072:/Nyah0mJjIiLXK179w2hOGwgp3ZZjtNj9ftamcnNAUFGo8VlPRPQT+QXAsWM6zJh:/wsIeM7yeJZZBPfUhB189sANT/AY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1244402F6A9C041EEE8524230297EDFB6C6F9BC0E2051314B27963B965A7319FB633143
sha3_384: 9a2ea86e101425000c36e05a22930aad9a8fa6a22b7c52f096fd2f65a86ba3e3984841c218c4d776f2c3548deb54c1b0
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Malware.AI.3775543220 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48092955
FireEyeTrojan.GenericKD.48092955
CAT-QuickHealTrojan.Spynoon
ALYacTrojan.GenericKD.48092955
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058d7ce1 )
K7GWTrojan ( 0058d7ce1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZedlaF.34232.bq4@aKUghShi
CyrenW32/Injector.ATR.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Generik.IIOAEGN
TrendMicro-HouseCallTrojanSpy.Win32.LOKIBOT.ERSUSBA22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.48092955
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan-spy.Noon.Hviu
Ad-AwareTrojan.GenericKD.48092955
SophosMal/Generic-S + Troj/Formbo-BXS
ComodoMalware@#2vnks560jk2r1
TrendMicroTrojanSpy.Win32.LOKIBOT.ERSUSBA22
McAfee-GW-EditionRDN/Generic PWS.y
EmsisoftTrojan.GenericKD.48092955 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.48092955
AviraTR/AD.Swotter.lzqzw
MAXmalware (ai score=84)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Lokibot.DECC!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PWS.C4964371
McAfeeRDN/Generic PWS.y
VBA32Trojan.Sabsik.FL
MalwarebytesMalware.AI.3775543220
APEXMalicious
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusTrojan.NSIS.Agent.S
FortinetW32/Kryptik.S!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.751bf1
PandaTrj/CI.A

How to remove Malware.AI.3775543220?

Malware.AI.3775543220 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment