Malware

Malware.AI.3791755452 removal tips

Malware Removal

The Malware.AI.3791755452 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3791755452 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Malware.AI.3791755452?


File Info:

name: 9582708B7617DC66ABB6.mlw
path: /opt/CAPEv2/storage/binaries/fc83ff939c1392017adcc56e9fcad63795e16cb88617153626ae17053d7c5023
crc32: 0275F2DD
md5: 9582708b7617dc66abb6759d14fadf6a
sha1: e9da05abb560dbef987a1a590f5b1c3bcb197aff
sha256: fc83ff939c1392017adcc56e9fcad63795e16cb88617153626ae17053d7c5023
sha512: f24fb7055254872578b38b713b9628e2e6596b7b5b569c38f715617e3707787ba44afd142ff444e9e4cbeaf8ba513d724ee690f3b653855b4662f4c1db798a99
ssdeep: 3072:VtpDdd/DnUn8QNJqmBVYp7GINjmw2rjd:LpHnm8QNJ7BVYp7nNjRO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F14EA00E1EB4619E11A6BB14EECF4B98A2EFCE571D8ECE6E5D4DF077AE1A004D42531
sha3_384: cd670c22fe9f4c9f8598538aed6139d62ce55ce0d33a69af9c93e4f0c3754bcb1a55e750e9d84003a7c735db81e45e27
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-11-04 18:16:59

Version Info:

Translation: 0x0000 0x04b0
Comments: GIthub
CompanyName: GIthub
FileDescription: GIthub
FileVersion: 1.7.0.7
InternalName: Test.exe
LegalCopyright: Copyright © 2022
LegalTrademarks: GIthub
OriginalFilename: Test.exe
ProductName: GIthub
ProductVersion: 1.7.0.7
Assembly Version: 1.7.0.7

Malware.AI.3791755452 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.DNP.lq0@aCSfZF
ClamAVWin.Packed.Msilperseus-9802572-0
McAfeeArtemis!9582708B7617
CylanceUnsafe
VIPREGen:Trojan.Heur.DNP.lq0@aCSfZF
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.2b8a60b5
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
SymantecBackdoor.Ratenjay
ESET-NOD32a variant of MSIL/Kryptik.VAV
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Gorgon.gen
BitDefenderGen:Trojan.Heur.DNP.lq0@aCSfZF
AvastWin32:Trojan-gen
TencentMsil.Trojan.Gorgon.Zfow
Ad-AwareGen:Trojan.Heur.DNP.lq0@aCSfZF
EmsisoftGen:Trojan.Heur.DNP.lq0@aCSfZF (B)
DrWebTrojan.PackedNET.253
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.9582708b7617dc66
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1236735
Antiy-AVLTrojan/MSIL.Kryptik
MicrosoftBackdoor:MSIL/Bladabindi.AJ
ArcabitTrojan.Heur.DNP.E993AB
ZoneAlarmHEUR:Trojan.MSIL.Gorgon.gen
GDataGen:Trojan.Heur.DNP.lq0@aCSfZF
GoogleDetected
AhnLab-V3Win-Trojan/MSILKrypt09.Exp
Acronissuspicious
BitDefenderThetaAI:Packer.BEB43AD71E
ALYacGen:Trojan.Heur.DNP.lq0@aCSfZF
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3791755452
TrendMicro-HouseCallTROJ_GEN.R002H0CK422
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:Vl0DH5pINa7rzqYl77xf8A)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.BGL!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.b7617d

How to remove Malware.AI.3791755452?

Malware.AI.3791755452 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment