Malware

What is “Malware.AI.3791348047”?

Malware Removal

The Malware.AI.3791348047 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3791348047 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Clears web history
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3791348047?


File Info:

name: 209B5D712154F0115CDB.mlw
path: /opt/CAPEv2/storage/binaries/9385c9a52a77da4439c6f973dcb0c7f7a7c629d0d10a368d1da88a7a44e3aff5
crc32: 6AD31CEA
md5: 209b5d712154f0115cdb9b2286058126
sha1: 4ebb141c7af9555f4606b95188c6899ab0dea864
sha256: 9385c9a52a77da4439c6f973dcb0c7f7a7c629d0d10a368d1da88a7a44e3aff5
sha512: 442deb9dc021d719b5f2f80c7f97495895136d136d10a7f7c2297f73b5020a3220535d1c313a01d295f4ed97e214fcf0236834715185e61ce95b5f50d7a88024
ssdeep: 1536:RtZxXcxVXWoOm4tAJP6k0H7lhXZwJqq3fD9CjStUinvN:RSxMolJyFHxUqq3fDeSt7vN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ACB3BF2A3D93D42BE4814830CAE4C2D61EBE6C173DC6626FFF80771F197068885E59B5
sha3_384: ee019bd3cead407ac06d1878c520f4b3bc44775be362c7d013b504985a43034920ce52abc2b7a9e35647d831c9674036
ep_bytes: 558bec6aff68e060400068f434400064
timestamp: 2011-08-06 14:45:53

Version Info:

Comments:
CompanyName: FastFire
FileDescription:
FileVersion: 1.0.1.23
InternalName: FastFire
LegalCopyright: @Microsift @Windows
LegalTrademarks:
OriginalFilename: ff.exe
PrivateBuild:
ProductName: ff
SpecialBuild:
Translation: 0x0419 0x04b0

Malware.AI.3791348047 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Cidox.4!c
MicroWorld-eScanGen:Variant.FakeAlert.85
FireEyeGeneric.mg.209b5d712154f011
CAT-QuickHealTrojan.Vundo.Gen
McAfeeGeneric Malware.bg!pec
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 002f86b71 )
AlibabaRansom:Win32/Cidox.24d8426d
K7GWTrojan ( 002f86b71 )
Cybereasonmalicious.12154f
BitDefenderThetaGen:NN.ZexaF.36302.gu0@a8kz0ick
CyrenW32/Virtumonde.CM.gen!Eldorado
SymantecTrojan.Zatvex
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.SFM
APEXMalicious
ClamAVWin.Trojan.Cidox-12
KasperskyTrojan-Ransom.Win32.Cidox.cs
BitDefenderGen:Variant.FakeAlert.85
NANO-AntivirusTrojan.Win32.Cidox.czajw
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Cidox [Drp]
RisingTrojan.Win32.ShutDown.fo (CLASSIC)
EmsisoftGen:Variant.FakeAlert.85 (B)
F-SecureTrojan.TR/Ransom.Cidox.csa
DrWebTrojan.Mayachok.based
VIPREGen:Variant.FakeAlert.85
TrendMicroTROJ_CIDOX.SMIC
McAfee-GW-EditionBehavesLike.Win32.FakeAVSecurityTool.ch
Trapminemalicious.high.ml.score
SophosTroj/Zatvex-A
IkarusTrojan.Win32.Vundo
GDataGen:Variant.FakeAlert.85
JiangminTrojan/Cidox.s
GoogleDetected
AviraTR/Ransom.Cidox.csa
Antiy-AVLTrojan[Ransom]/Win32.Cidox
XcitiumTrojWare.Win32.KryptiK.EA@3z76zp
ArcabitTrojan.FakeAlert.85
ViRobotDropper.Cidox.Gen.C
ZoneAlarmTrojan-Ransom.Win32.Cidox.cs
MicrosoftTrojan:Win32/Vundo.OD
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Cidox.R10194
VBA32Hoax.Cidox
ALYacGen:Variant.FakeAlert.85
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3791348047
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_CIDOX.SMIC
TencentWin32.Trojan.Cidox.Dkjl
YandexTrojan.GenAsa!7iv57JJFEgU
SentinelOneStatic AI – Suspicious PE
FortinetW32/Cidox.GS!tr
AVGWin32:Cidox [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.3791348047?

Malware.AI.3791348047 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment