Malware

Malware.AI.3869205404 (file analysis)

Malware Removal

The Malware.AI.3869205404 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3869205404 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Malware.AI.3869205404?


File Info:

name: D09F34032DABEAD42E8D.mlw
path: /opt/CAPEv2/storage/binaries/8d50d61731d105227811744b7b2b16f340151cbde58c45d4a5ef246f85f3586d
crc32: 06C43398
md5: d09f34032dabead42e8dac1dac5cd845
sha1: 80365d556ade76dfa1b6ec9e016f257c357eff44
sha256: 8d50d61731d105227811744b7b2b16f340151cbde58c45d4a5ef246f85f3586d
sha512: c9bb9d1f2dde5dbabf91d19281a3ef089324738dd80cc22927fca96bcdca0e5aa80b15885fa513797c126abd1149cdc4440216da6be43ea8d50128f76038a9d6
ssdeep: 12288:ZLwhldRQHStB/OvS1wvXA/VLPtpjQO8N/0WCSo3rFlVR6hDJiuUAks78cjVDa/Z0:VwhtPL/AyL3EO8N2hlVR6Nvpa/ZS1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B815BE0E2658E4CBC816677DFDBD8A299439A97F2A53C3B6B1003613742A7D0DD07E78
sha3_384: 39a81ca12c0c33e584aba4e48e72bd5ba8d6077673cbcd107388e691edd777f8d9fafb6da867c9d93ceaa9707553b0ce
ep_bytes: 6379e97133106df636f16467b4bb0cdd
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.3869205404 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.93251
FireEyeGeneric.mg.d09f34032dabead4
CAT-QuickHealTrojan.Skeeyah.J1
McAfeePacked-FJB!D09F34032DAB
MalwarebytesMalware.AI.3869205404
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005393141 )
BitDefenderGen:Variant.Symmi.93251
K7GWTrojan ( 005376b01 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Zusy.EM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIRH
APEXMalicious
ClamAVWin.Packed.Dridex-9860931-1
KasperskyHEUR:Trojan.Win32.Generic
RisingTrojan.Kryptik!1.B34D (CLASSIC)
TACHYONTrojan/W32.Selfmod
EmsisoftGen:Variant.Symmi.93251 (B)
ComodoTrojWare.Win32.Kryptik.TLS@812zm8
DrWebTrojan.PackedENT.183
ZillyaTrojan.Generic.Win32.882819
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosML/PE-A + Mal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.encsw
AviraHEUR/AGEN.1141086
Antiy-AVLTrojan/Generic.ASBOL.C549
SUPERAntiSpywareTrojan.Agent/Gen-Razy
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.93251
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Packed.R357404
BitDefenderThetaGen:NN.ZexaF.34182.2CW@am2hnHh
MAXmalware (ai score=82)
VBA32Trojan.Glupteba
PandaTrj/Genetic.gen
TencentTrojan.Win32.Kryptik.gifya
YandexTrojan.GenAsa!0xM7zILK7cg
IkarusTrojan.Win32.Tiggre
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.32dabe
AvastWin32:MalwareX-gen [Trj]

How to remove Malware.AI.3869205404?

Malware.AI.3869205404 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment