Malware

About “Malware.AI.3897767324” infection

Malware Removal

The Malware.AI.3897767324 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3897767324 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3897767324?


File Info:

name: F6EF60B51A968FA1ED76.mlw
path: /opt/CAPEv2/storage/binaries/c3be93e2398e6488bea1dd82d1b82de3b8ba3936b99aed4e621f1cba89c0bc4a
crc32: 28747C23
md5: f6ef60b51a968fa1ed76b4715abca5b8
sha1: e3aa2e388b6bc56fcc9ecd49f8adf5093f8a6330
sha256: c3be93e2398e6488bea1dd82d1b82de3b8ba3936b99aed4e621f1cba89c0bc4a
sha512: 4c6d9ab521e0db80f32a6050e613102bf27b1dd03e3c29d965520bdc90397ec7d7262b4bbf95bcc57ba319fd1c92953d76cfc693bd5d5feb0772a1b9ed002b83
ssdeep: 12288:dsHzOUNUSB/o5LsI1uwajJ5yvv1l2OE6m/YY+fQsuhxwx:0iUmSB/o5d1ubcvJEh/YY+osuh2x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199D4F039A6C0A835C36E39F0FC959AA98558DE001AD51FD5BEDFF7B9B8F51208C38181
sha3_384: 65912c737e7e0b21546a7da81973f9822cefee0e830380ccc5215e8ecf133d34431bf25b77e3920fc80587a0e1d963e1
ep_bytes: 60be00b04c008dbe0060f3ffc78740f7
timestamp: 2023-02-23 17:34:51

Version Info:

FileVersion: 1.0.0.33
Comments: http://www.autoitscript.com/autoit3/
FileDescription: (Tran)sfer de (P)rofil
ProductVersion: 4.0
CompanyName: MAV
LegalCopyright: MAV
Translation: 0x040c 0x04b0

Malware.AI.3897767324 also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
McAfeeArtemis!F6EF60B51A96
MalwarebytesMalware.AI.3897767324
Elasticmalicious (moderate confidence)
APEXMalicious
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.jc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f6ef60b51a968fa1
SophosGeneric ML PUA (PUA)
JiangminTrojan.Script.awbz
VBA32BScope.Trojan.Script
Cylanceunsafe
RisingTrojan.Generic@AI.97 (RDML:29QMmwu83kfAVFS04A9buQ)
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Malware.AI.3897767324?

Malware.AI.3897767324 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment