Malware

Should I remove “Malware.AI.3806498687”?

Malware Removal

The Malware.AI.3806498687 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3806498687 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3806498687?


File Info:

name: 12BBDE8297619E7C0195.mlw
path: /opt/CAPEv2/storage/binaries/3719e6d25630a4b094c641a6bce2f7bec17444dc3672b76147e4daf2ed770987
crc32: 2AF451E8
md5: 12bbde8297619e7c0195e0b5931b83d7
sha1: f7c840de03a22da4946a6690ace1eb3069d39bd9
sha256: 3719e6d25630a4b094c641a6bce2f7bec17444dc3672b76147e4daf2ed770987
sha512: ebb9c7e2a881755310ff7052e8da17e1460da2d478b6376d0b1562e2b500af1d817972bf2648d2deef074345f336bcf011188488b95d559d0b5682b455ef088d
ssdeep: 49152:l7ZQbAVNhFHg1Zt7XXxQu7859G9q5hfXcGnfrCbv66Snoh9oa4X0Z7Ea04W+x:KINhoHjXyu7aG45hfXM6Eh9oau0ZVZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170D5331662E6D124CABF4D7558A8C5344B337C5BE974C71E848C108E9FA3351FAD2BB2
sha3_384: ce0e1e897146ecacedd4627d6dddff1af54ace63bb207aa5fe08beec231368a0aabb0ccb2523c3b79c3f6631e68bb666
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-04-07 18:21:36

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: DiagnosticsHub.DataWarehouse.ServiceModule
FileVersion: 16.6.30007.001
InternalName: Microsoft.DiagnosticsHub.DataWarehouse.ServiceModule.dll
LegalCopyright: Copyright © Microsoft 2019
OriginalFilename: Microsoft.DiagnosticsHub.DataWarehouse.ServiceModule.dll
ProductName: DiagnosticsHub.DataWarehouse.ServiceModule
ProductVersion: DiagHub_master_caa7112941ff2d97630d1792b58bade575cb2c12
Assembly Version: 16.0.0.0

Malware.AI.3806498687 also known as:

LionicTrojan.MSIL.Crypt.4!c
DrWebTrojan.KillProc2.17313
CynetMalicious (score: 100)
FireEyeTrojan.Agent.FSWX
ALYacTrojan.Agent.FSWX
SangforTrojan.MSIL.Crypt.gen
K7GWTrojan ( 0058df9b1 )
K7AntiVirusTrojan ( 0058df9b1 )
CyrenW32/MSIL_Troj.BXU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AEFG
TrendMicro-HouseCallTROJ_FRS.0NA103B522
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderTrojan.Agent.FSWX
MicroWorld-eScanTrojan.Agent.FSWX
TencentMsil.Trojan.Crypt.Dxxb
Ad-AwareTrojan.Agent.FSWX
SophosMal/Generic-S
TrendMicroTROJ_FRS.0NA103B522
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Agent.FSWX (B)
IkarusTrojan.MSIL.Crypt
GDataTrojan.Agent.FSWX
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Agent.FSWX
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
McAfeeArtemis!12BBDE829761
MAXmalware (ai score=83)
MalwarebytesMalware.AI.3806498687
PandaTrj/GdSda.A
APEXMalicious
SentinelOneStatic AI – Suspicious PE
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Malware.AI.3806498687?

Malware.AI.3806498687 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment