Malware

Malware.AI.3917876538 removal tips

Malware Removal

The Malware.AI.3917876538 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3917876538 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3917876538?


File Info:

name: 1F3C66F1DBF8D6C17FB4.mlw
path: /opt/CAPEv2/storage/binaries/818d217eaf7bd628f950e1d76cb407b7b9a21031873ab14034cf3013ecb0f5ac
crc32: 02C088EC
md5: 1f3c66f1dbf8d6c17fb4eaeebb7f0972
sha1: 533ce67d1c0074fce834f32bcd5ab28df2579392
sha256: 818d217eaf7bd628f950e1d76cb407b7b9a21031873ab14034cf3013ecb0f5ac
sha512: b64520165ead679e3641bbafeba78208cd1db5042f9e23be9c88a15049de87d8579fe02c09528d416a4f119c6a0e36045a3e64e69fe365f55a6ae7c7c04022ad
ssdeep: 3072:l6yxkKOiQs8J+AEMrSJeHqHLl/DPJoAiKzREUAXFASGTVtQWU94/TETc9BgnDE3S:lQKDJLh/DPWAiKz28tnQToBgnDMMM0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163646126AE60707BE50795F1252E936A280C1E7A2390EC07B741BB9574382F3B5F275F
sha3_384: 3f6d61661e939b5c33a75f98f0037df08423e00c0c60006af87470a67388ce85eba168d90ff91a7cd723601dae1ab509
ep_bytes: 68cc434000e8f0ffffff000000000000
timestamp: 1998-06-07 10:11:02

Version Info:

0: [No Data]

Malware.AI.3917876538 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.471328
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.1f3c66f1dbf8d6c1
CAT-QuickHealTrojan.VbkryptVMF.S19738950
ALYacGen:Variant.Zusy.471328
MalwarebytesMalware.AI.3917876538
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.SHeur4.TAL
CyrenW32/Vobfus.SF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.VB.ASS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.kwoo
BitDefenderGen:Variant.Zusy.471328
NANO-AntivirusTrojan.Win32.VBKrypt.cqkyhe
AvastWin32:VB-ABOE [Trj]
TencentTrojan.Win32.VBKrypt.hm
TACHYONTrojan/W32.VB-VBKrypt.335872.Z
EmsisoftGen:Variant.Zusy.471328 (B)
F-SecureTrojan.TR/VB.Agent.aboe.1
DrWebTrojan.VbCrypt.250
VIPREGen:Variant.Zusy.471328
TrendMicroTROJ_AGENT_008146.TOMB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.moderate.ml.score
SophosW32/SillyFDC-HI
SentinelOneStatic AI – Malicious PE
AviraTR/VB.Agent.aboe.1
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!S
ArcabitTrojan.Zusy.D73120
ViRobotTrojan.Win32.A.VBKrypt.331776.BR
ZoneAlarmTrojan.Win32.VBKrypt.kwoo
GDataGen:Variant.Zusy.471328
GoogleDetected
AhnLab-V3Trojan/Win.VBKrypt.R558949
McAfeeVBObfus.dk
MAXmalware (ai score=84)
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_AGENT_008146.TOMB
RisingTrojan.VBEx!1.99EE (CLASSIC)
YandexTrojan.GenAsa!Tx+92+LZ/Uo
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36250.umX@aWPv9Tg
AVGWin32:VB-ABOE [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.3917876538?

Malware.AI.3917876538 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment