Malware

Malware.AI.3790662888 (file analysis)

Malware Removal

The Malware.AI.3790662888 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3790662888 virus can do?

  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3790662888?


File Info:

name: C88CA42CDC17EC80A1AF.mlw
path: /opt/CAPEv2/storage/binaries/0e8346da5c3480e466240c1839d331d60e4926ee56990c73d80593ade014d6fc
crc32: 766B01B2
md5: c88ca42cdc17ec80a1afa5ebb1bb581d
sha1: 681cef9ee8c743a26f4617ba6f215a91de779cd3
sha256: 0e8346da5c3480e466240c1839d331d60e4926ee56990c73d80593ade014d6fc
sha512: 44dc145c2870e954d59e48e63adad1168fa2ccc541b68c8a25336c8da238d993b03094df129abd498c7a57ac2c14871338251e8db9634d422d95af8b0a27cca2
ssdeep: 12288:lEcqu215SiUMoK+yOiCEe5Ro69+Xn6BEdc53Arc8NAu61ZkxNqRzwPN8k:DD2W+oK+HEju+Xn2EdK9O6wxNqRMN8k
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1454523044D6CD7C1DA9762308996816A727FFDA81EE146C37085327F4D3C3EA893ADDA
sha3_384: 12bc8aa703ba9e3997e90db8c802f9faf7619c09906fd345423fcf2c361cb9bae87e35706e1ad93a946e0408f572e58c
ep_bytes: e805030000e9c3fdffffcccccccccc3b
timestamp: 2009-07-13 23:11:01

Version Info:

CompanyName: Microsoft Corporation
FileDescription: x86 Performance Counter Host
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: perfhost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: perfhost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Malware.AI.3790662888 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
ClamAVWin.Virus.Expiro-9954755-0
FireEyeGeneric.mg.c88ca42cdc17ec80
CAT-QuickHealW32.Expiro.R3
ALYacWin32.Expiro.Gen.7
MalwarebytesMalware.AI.3790662888
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Expiro.AU.gen!Eldorado
SymantecW32.Xpiro.J!dam
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Expiro.CQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureTrojan.TR/Patched.Gen
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
SophosW32/Moiva-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
AviraTR/Patched.Gen
MAXmalware (ai score=82)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
Acronissuspicious
McAfeeGenericRXAA-AA!C88CA42CDC17
DeepInstinctMALICIOUS
Cylanceunsafe
PandaW32/Moyv.A
RisingTrojan.Generic@AI.84 (RDMK:cmRtazoEv3ow+Jp6faDmb6rObDeT)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Malware.AI.3790662888?

Malware.AI.3790662888 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment