Malware

Malware.AI.3828318304 removal tips

Malware Removal

The Malware.AI.3828318304 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3828318304 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3828318304?


File Info:

name: F7502A2E0070A00B47A5.mlw
path: /opt/CAPEv2/storage/binaries/285658e63075508bd9475d8998644e5b38c0def3ffb65b45112ce6051ea95ad8
crc32: 005139DD
md5: f7502a2e0070a00b47a5dbaa4ef31ff5
sha1: 7ae91064cf34435bb7c5ec21e42253e5089195ae
sha256: 285658e63075508bd9475d8998644e5b38c0def3ffb65b45112ce6051ea95ad8
sha512: 3686e34ac15379d5581c3c16b3670a480a251c5a1e20b9a2f437a64f4fab912553d8443a96ed835e7f7480cf58fd1d19f9d10359acba20d1a2cf32b0145f80c2
ssdeep: 12288:lQ1D0vKEnE31fq3UQ2v5e3RmoJw1Hcp41/2POh0pa7:lQ1zKhmoJuHF1K2v7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10DC41241B541C1B7D3000170319EA67BE17DE1316AE1F1B3FB5AAE692DB4EB3B90A05B
sha3_384: 30c891497b9fe544f5854b73b6a8cf8a4e033609d6cb61ef29ca3c37d547543e542a63bfed453e9df75b1426ed3d0742
ep_bytes: e86f2b000050e85f3601000000000090
timestamp: 2008-08-02 07:56:45

Version Info:

0: [No Data]

Malware.AI.3828318304 also known as:

BkavW32.Common.08E673E5
LionicTrojan.Win32.Bototer.4!c
SkyhighBehavesLike.Win32.Dropper.hc
MalwarebytesMalware.AI.3828318304
SangforTrojan.Win32.Agent.Vmql
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.36792.ar0@aKqdEglb
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Bototer-28
RisingTrojan.Generic@AI.100 (RDML:KQdy1NMXHIqBlgrOtYCM5w)
TACHYONTrojan/W32.Chifrax.564685
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.f7502a2e0070a00b
SophosGeneric Reputation PUA (PUA)
JiangminTrojanDropper.Bototer.db
VaristW32/S-9a0e6078!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
KingsoftWin32.Troj.Undef.a
MicrosoftPUA:Win32/Presenoker
XcitiumWorm.Win32.Dropper.RA@1qraug
GDataWin32.Trojan.PSE.13YMLT9
GoogleDetected
McAfeeArtemis!F7502A2E0070
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Valcaryx
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002V01JG23
SentinelOneStatic AI – Suspicious SFX
MaxSecureTrojan.Malware.208413131.susgen
FortinetW32/Bototer.MI!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.4cf344
AvastWin32:Trojan-gen

How to remove Malware.AI.3828318304?

Malware.AI.3828318304 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment