Malware

How to remove “Malware.AI.3903114825”?

Malware Removal

The Malware.AI.3903114825 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3903114825 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Malware.AI.3903114825?


File Info:

name: 7A2292C55E739610F707.mlw
path: /opt/CAPEv2/storage/binaries/e556027f740f1e37db81f3a0ead53a6005c8cdf4da16691bfee7cf0f2979237a
crc32: DECD3438
md5: 7a2292c55e739610f70746365d71cb04
sha1: 20521648abd11ac9a48f4e33738b61c88731e2aa
sha256: e556027f740f1e37db81f3a0ead53a6005c8cdf4da16691bfee7cf0f2979237a
sha512: 79ac726013488a0cfd4ee79f501493603de9ad8adc616853ad2e3b95dbbebe0ae20428fa1c77ed4e7402310a68c7aae8ff5978c584db5058765857c45e8cd9ce
ssdeep: 6144:/axU76Eo8ey9+Nn4+keP+xGDWx6B+aorHBl:EzLqHe+GImYDL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C34E12646D298F7C1E502734C9B3AECBD3A2D818104071B52CDF91E59F27AE7E1AF25
sha3_384: 13ea9b5dc8b9df80c3976c967fddf8c65bc9b38c376954ec4a55fd13b87d08fadd18de064b446a224f1fcaf860019188
ep_bytes: 68384a00006849437862508d55fc52ff
timestamp: 2004-07-04 02:37:13

Version Info:

0: [No Data]

Malware.AI.3903114825 also known as:

LionicHacktool.Win32.Krap.x!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.Cerber.2
FireEyeGeneric.mg.7a2292c55e739610
McAfeeArtemis!7A2292C55E73
MalwarebytesMalware.AI.3903114825
ZillyaTrojan.Zbot.Win32.196421
SangforSpyware.Win32.Zbot.ZR
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanPSW:Win32/MalOb.47c8197a
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.55e739
VirITTrojan.Win32.Panda.OX
CyrenW32/Zbot.AX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.ZR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1282
KasperskyPacked.Win32.Krap.ae
BitDefenderGen:Heur.Ransom.Cerber.2
NANO-AntivirusTrojan.Win32.Zbot.dchlma
AvastWin32:MalOb-IJ [Cryp]
TencentMalware.Win32.Gencirc.114c06bb
Ad-AwareGen:Heur.Ransom.Cerber.2
EmsisoftGen:Heur.Ransom.Cerber.2 (B)
DrWebTrojan.PWS.Panda.387
VIPREPacked.Win32.Zbot.gen.y.7 (v)
TrendMicroTROJ_GEN.R002C0DB922
McAfee-GW-EditionBehavesLike.Win32.Generic.dt
SophosMal/Generic-R + Mal/Zbot-U
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Ransom.Cerber.2
JiangminTrojanSpy.Zbot.anmw
AviraHEUR/AGEN.1237544
Antiy-AVLTrojan[Packed]/Win32.Krap
GridinsoftRansom.Win32.Zbot.sa
ZoneAlarmPacked.Win32.Krap.ae
MicrosoftPWS:Win32/Zbot.gen!Y
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.5790909A1F
ALYacGen:Heur.Ransom.Cerber.2
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DB922
RisingMalware.Zbot!8.E95E (TFE:2:jkkQsDHXOkI)
YandexTrojan.GenAsa!t4JOG2RxBX0
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Zbot.U!tr
AVGWin32:MalOb-IJ [Cryp]
PandaTrj/Sinowal.XHV
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3903114825?

Malware.AI.3903114825 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment