Malware

Should I remove “Malware.AI.3781876722”?

Malware Removal

The Malware.AI.3781876722 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3781876722 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.3781876722?


File Info:

crc32: 56C54691
md5: 3b4c06a45ee32bb84b12b4703fd131ae
name: 3B4C06A45EE32BB84B12B4703FD131AE.mlw
sha1: 3977bd52bce3f8a8bb1dd780afe823ccd54c7ade
sha256: 2c47eb23ba1ee0ac5e7d880c3c57f4325c97593b492e801c0d5a99adc4318648
sha512: 55b13f1aef08824d8682086ce712ed7243122d624150945a9fcf662c8b14a87edeefe894222034384cb89e736ec7807c65a3522475b19472fdb14a298708ead0
ssdeep: 12288:VSnxZ0EG3KQyTs4XlhyI/vbU0x7bUIv3Y/qtMGNSpXBrUBziyL/9qyw0cVzUJB7:VSP8Ig/IMGsBcWyLgP0cKHMvzU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Computer/Spiele-Info.net 2013
Assembly Version: 1.0.1.0
InternalName: WellKnownServiceTypeEnt.exe
FileVersion: 1.3.1.0
CompanyName: Computer/Spiele-Info.net
LegalTrademarks: Computer/Spiele-Info.net
Comments: 2D-GameEngine by 3r0rXx
ProductName: VMML
ProductVersion: 1.3.1.0
FileDescription: VMML
OriginalFilename: WellKnownServiceTypeEnt.exe

Malware.AI.3781876722 also known as:

LionicTrojan.MSIL.Crypt.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.934
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.2bce3f
CyrenW32/Trojan.GNN.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ABZN
APEXMalicious
AvastMSIL:Agent-BCI [Trj]
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderGen:Variant.Bulz.564713
MicroWorld-eScanGen:Variant.Bulz.564713
Ad-AwareGen:Variant.Bulz.564713
BitDefenderThetaGen:NN.ZemsilF.34796.hn0@aeyUZ5l
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.3b4c06a45ee32bb8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
MicrosoftTrojan:MSIL/NanoBot.D!MTB
GDataMSIL.Malware.Injector.YRCO3N
McAfeeArtemis!3B4C06A45EE3
MAXmalware (ai score=83)
MalwarebytesMalware.AI.3781876722
IkarusWin32.SuspectCrc
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ABZN!tr
AVGMSIL:Agent-BCI [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.3781876722?

Malware.AI.3781876722 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment