Malware

Malware.AI.3869256369 removal instruction

Malware Removal

The Malware.AI.3869256369 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3869256369 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Malware.AI.3869256369?


File Info:

name: 3A32C491EEA80DA8D83E.mlw
path: /opt/CAPEv2/storage/binaries/a417447118e65ea17c0b140fb2f04cfdc99924b9cdcbd734a8c8d762c11a1333
crc32: A96E7687
md5: 3a32c491eea80da8d83eb0fd6b598115
sha1: b8d54ff48696ff56c7a35724010cf119b500b221
sha256: a417447118e65ea17c0b140fb2f04cfdc99924b9cdcbd734a8c8d762c11a1333
sha512: ebca0751977530aa14a25290fd7caae9182ca947eb0bedc5c7df7109d2dfee6d4660746c4af4726b53dde4db62ea5cdb4cafc5fdd8e1654ec3bfa0d4836d6ab0
ssdeep: 6144:dZsqqqDLZi0DfheW2RkpfnYVqI+iB2qc4G8D6tfj4B75DuCMQ:defqnZi0D5e9TqI+k2iG8D6V25KCMQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA24CF23F540A0B7D9A315B06EA9732BA2FFC934A234EC83D3744D693575592662E30F
sha3_384: dd24cf651a9e4a0fbecf66547d9da6faf366c3a6bf9b9b13094c7aed587b0261b38e41725c18b002dd51bcda2e43f913
ep_bytes: e9d535feff0000000000000000000000
timestamp: 2012-10-05 15:31:41

Version Info:

0: [No Data]

Malware.AI.3869256369 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeePWS-Zbot.gen.vo
CylanceUnsafe
VIPRETrojan-PWS.Win32.Zbot.aac (v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderGen:Heur.Mint.Dreidel.nmX@xaxEeab
BaiduWin32.Trojan.Zbot.a
CyrenW32/Zbot.BR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Zbot.YW
APEXMalicious
AvastSf:Crypt-BR [Trj]
ClamAVWin.Spyware.Zbot-1275
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Heur.Mint.Dreidel.nmX@xaxEeab
TencentTrojan.Win32.Zbot.aaw
Ad-AwareGen:Heur.Mint.Dreidel.nmX@xaxEeab
EmsisoftGen:Heur.Mint.Dreidel.nmX@xaxEeab (B)
ComodoTrojWare.Win32.Zbot.NEWA@4qfujn
DrWebTrojan.PWS.Panda.2401
TrendMicroTSPY_ZBOT.SMQF
McAfee-GW-EditionBehavesLike.Win32.ZBot.dh
FireEyeGeneric.mg.3a32c491eea80da8
SophosML/PE-A + Mal/Zbot-HX
IkarusTrojan-Spy.Banker.Citadel
GDataGen:Heur.Mint.Dreidel.nmX@xaxEeab
JiangminTrojan/Generic.azjdg
AviraTR/Spy.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.262C37
ArcabitTrojan.Mint.Dreidel.E2F0D7
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
MicrosoftPWS:Win32/Zbot!CI
AhnLab-V3Spyware/Win32.Zbot.R27121
Acronissuspicious
VBA32SScope.Trojan.FakeAV.01110
ALYacGen:Heur.Mint.Dreidel.nmX@xaxEeab
MalwarebytesMalware.AI.3869256369
TrendMicro-HouseCallTSPY_ZBOT.SMQF
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpGEjSuHZbBar/WM/1Pcx9b)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AT!tr
BitDefenderThetaGen:NN.ZexaF.34084.nmX@aaxEeab
AVGSf:Crypt-BR [Trj]

How to remove Malware.AI.3869256369?

Malware.AI.3869256369 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment