Malware

Should I remove “Malware.AI.3918815232”?

Malware Removal

The Malware.AI.3918815232 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3918815232 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3918815232?


File Info:

name: 849F7122600073083D2F.mlw
path: /opt/CAPEv2/storage/binaries/2d3cbd6a4ee95a6940e508f1d1570e25201e1fecfa966c406bfde4525a82e74b
crc32: 78FA493F
md5: 849f7122600073083d2f2f6966539045
sha1: cffe2b10ce2565cf516b5ba0c4f2622e1e22b9da
sha256: 2d3cbd6a4ee95a6940e508f1d1570e25201e1fecfa966c406bfde4525a82e74b
sha512: 6628bc2a22e18276b30e0e5f7faa45d31459b5903ecd735f92ade8b6545fe40df6e035d507df3656ba523a991f084b016a6a4f461d26dd868634326fe1f534c2
ssdeep: 6144:rGiDy327c5Q76IMVPPHb9tD86pHksfbEyF/UnKKPCvYgC0:Hg1rxnHbbT1fXGP3gC0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18264124AE7C154FBD5E745722A7AFBF8FBF901D10CA14E8767404EA62CFE4420D1A286
sha3_384: eb1b23daaf1e9c46694f93db056505ffbb130c405c3faa3997a9e19013a7a06e174113609e90a1e83ac4765f3b5e9d23
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Malware.AI.3918815232 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Inject.4!c
DrWebTrojan.Siggen15.64496
MicroWorld-eScanTrojan.GenericKD.38200761
FireEyeTrojan.GenericKD.38200761
ALYacTrojan.GenericKD.38200761
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.260007
CyrenW32/Injector.ARI.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQRT
TrendMicro-HouseCallTROJ_FRS.0NA103L721
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.anyht
BitDefenderTrojan.GenericKD.38200761
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38200761
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.ergpv@0
TrendMicroTROJ_FRS.0NA103L721
McAfee-GW-EditionRDN/GenericU
EmsisoftTrojan.GenericKD.38200761 (B)
IkarusTrojan.Win32.Injector
GDataWin32.Trojan-Stealer.FormBook.8SGNGE
AviraTR/AD.Swotter.lbjoj
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D246E5B9
MicrosoftTrojan:Win32/Lokibot.SIS!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Lokibot.C4818126
McAfeeRDN/GenericU
MAXmalware (ai score=83)
VBA32Trojan.Inject
MalwarebytesMalware.AI.3918815232
APEXMalicious
FortinetW32/Injector.EQRT!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A

How to remove Malware.AI.3918815232?

Malware.AI.3918815232 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment