Malware

What is “Malware.AI.3921701683”?

Malware Removal

The Malware.AI.3921701683 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3921701683 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the Formbook malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.3921701683?


File Info:

name: B9E47B59D446DEDCBE25.mlw
path: /opt/CAPEv2/storage/binaries/756983f446594a0e8461a92f0ebc8fd519016a164664b0546156fca6a2c352f8
crc32: 3CD0E22C
md5: b9e47b59d446dedcbe2576b51a2e4e58
sha1: 8be764b4575ac9a69a92e5226e88e8fad6dd43ac
sha256: 756983f446594a0e8461a92f0ebc8fd519016a164664b0546156fca6a2c352f8
sha512: 2cd16c8bc3c12ba46a8c286492a5c697f48464bdd16baffcc74e7a57cafff1231eb05965bb20a6642452a2faeffa173092e7bcce982b869bcb5cefd9de8d4558
ssdeep: 6144:/Ya6L8N+zZH3zbF1crv+ZJzKwKh8Kw1FsWhCj00jgkxmh:/YBA+zZH3zgYEwKh8dFsWhCLj6h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F054120591B8C4B2EDB343320D7B43B6EEF6A71269BC834E03586BAE7D63795651D302
sha3_384: a45010250de1a6a0f95c6c99718e89fb729737d61a1b1f468943c866ff220d2c94dad7792456213785acaed40dab0781
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:56:47

Version Info:

CompanyName: tarapatch
FileDescription: lanthania
FileVersion: 35.50.69.61
LegalCopyright: Copyright redraft
ProductName: 35.50.69.61
Translation: 0x0409 0x04b0

Malware.AI.3921701683 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68154048
FireEyeGeneric.mg.b9e47b59d446dedc
SkyhighBehavesLike.Win32.Generic.dc
McAfeeArtemis!B9E47B59D446
Cylanceunsafe
ZillyaTrojan.Strab.Win32.5740
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/FormBook.e04e257d
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
VirITTrojan.Win32.GenusT.DOGB
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.ETCS
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.F0D1C00GD23
KasperskyHEUR:Trojan.Win32.Strab.pef
BitDefenderTrojan.GenericKD.68154048
NANO-AntivirusTrojan.Win32.Strab.jxgjuy
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Strab.Nqil
EmsisoftTrojan.GenericKD.68154048 (B)
F-SecureHeuristic.HEUR/AGEN.1364590
VIPRETrojan.GenericKD.68154048
TrendMicroTROJ_FRS.0NA103GE23
Trapminemalicious.moderate.ml.score
SophosTroj/Inject-JBY
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1373280
VaristW32/Ninjector.JO.gen!Eldorado
Antiy-AVLTrojan/Win32.Lokibot
KingsoftWin32.Trojan.Strab.pef
MicrosoftTrojan:Win32/FormBook.SSS!MTB
XcitiumMalware@#3rpfn7qyosu5d
ArcabitTrojan.Generic.D40FF2C0
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
GDataTrojan.GenericKD.68154048
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R585815
VBA32Trojan.Formbook
ALYacTrojan.GenericKD.68154048
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3921701683
PandaTrj/CI.A
RisingTrojan.Injector!1.E835 (CLASSIC)
YandexTrojan.Igent.b0t6iz.7
IkarusTrojan.Win32.Injector
FortinetNSIS/Agent.DCAC!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudMalware

How to remove Malware.AI.3921701683?

Malware.AI.3921701683 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment