Malware

How to remove “Malware.AI.3896115729”?

Malware Removal

The Malware.AI.3896115729 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3896115729 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the WarzoneRAT malware family
  • Accesses or creates Warzone RAT directories and/or files

How to determine Malware.AI.3896115729?


File Info:

name: EBA5CE23C4561F9B447B.mlw
path: /opt/CAPEv2/storage/binaries/49780c221f6bda8993267a99208918b0608fac2ccfbe72e362c4771b8b698275
crc32: 96BA89FF
md5: eba5ce23c4561f9b447b4594c4019f1d
sha1: c250b97a227ec07f1575cbe46b6d6ef5d8c4cf29
sha256: 49780c221f6bda8993267a99208918b0608fac2ccfbe72e362c4771b8b698275
sha512: 715e86d015b6e3e02bbb1e8a472f2c364e4146ec7ae8c1c71c1b4e50dc92ec494551cf6e973cadc7a4b80f6303be5e5dcb7de4f330f8f71468760a0bbbb68188
ssdeep: 12288:GMuYv3Qip6uPz7XdRybylWsn9cNfvFI1X/MW:3u+zjd
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T148B5B564E3951101E5A7A77F72A08BD0889E3C415C6EA78F5E470BC6CA2E2F4790C6F7
sha3_384: 2e57adbc675e0531ed2a6a3b72c5d0e17214deb44d6dc42325666eee0c3a08e80b7a23f08b3a60f04d547ac34ea1cca1
ep_bytes: e83a040000e95bfeffffff255c624400
timestamp: 2022-08-17 20:52:48

Version Info:

0: [No Data]

Malware.AI.3896115729 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.133082
FireEyeGeneric.mg.eba5ce23c4561f9b
McAfeeArtemis!EBA5CE23C456
MalwarebytesMalware.AI.3896115729
VIPREGen:Variant.Fragtor.133082
K7GWTrojan ( 005972101 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FXWU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Streamer.aoy
BitDefenderGen:Variant.Fragtor.133082
NANO-AntivirusTrojan.Win32.Streamer.jrszrj
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Fragtor.133082
SophosGeneric ML PUA (PUA)
DrWebTrojan.Inject4.40636
McAfee-GW-EditionBehavesLike.Win32.Generic.vz
EmsisoftGen:Variant.Fragtor.133082 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Fragtor.133082
JiangminTrojan.Streamer.gd
AviraTR/Kryptik.wxuph
Antiy-AVLTrojan/Generic.ASMalwS.5123
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGen:Variant.Fragtor.133082
MAXmalware (ai score=88)
RisingTrojan.Kryptik!8.8 (TFE:5:gndFH2yOFv)
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.3896115729?

Malware.AI.3896115729 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment