Malware

Malware.AI.3925551196 removal instruction

Malware Removal

The Malware.AI.3925551196 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3925551196 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Appears to use command line obfuscation
  • A script or command line contains a long continuous string indicative of obfuscation
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3925551196?


File Info:

name: 922C52DEE4BF9D890D3E.mlw
path: /opt/CAPEv2/storage/binaries/842e7498809358796971cc1258bec28571b132b35a67423209e09b156f935361
crc32: 07D1F535
md5: 922c52dee4bf9d890d3eee771f4550f1
sha1: 977e301eac7108733613ceff2e7cadc71a9bcd88
sha256: 842e7498809358796971cc1258bec28571b132b35a67423209e09b156f935361
sha512: 4fe4fdf30b6d1583bf64cb009005762c5e3f3407b61644028ff57cc44dc8a9a870dc69e12255eb64c0d178c9c74616338b1eed412ef5e8b85c66145e52cddf73
ssdeep: 49152:+UgtLQa10rsno+8ObH3wm5A6avZRwLe9i7XnjefoOCFFVG1StDaymg3WeVWmxWTj:4tLQa1WsPrbXwsAZvALeNj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BE53A91FEEF90F1F603493054AB523F6F3166098739DAC7CA441E57E82B6E2067235A
sha3_384: f2c97306e22b7d67ae1971664fafa64a8cfb504bc1241c8a1c1320601bcf2074ce5d7fc8ffd89d0354e555b67db74402
ep_bytes: 83ec0c8b44240c8d5c24108944240489
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.3925551196 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Ursu.17457
FireEyeGeneric.mg.922c52dee4bf9d89
SkyhighBehavesLike.Win32.Trojan.wh
ALYacGen:Variant.Ser.Ursu.17457
Cylanceunsafe
ZillyaTrojan.RanumBot.Win32.574
SangforTrojan.Win32.Skeeyah.Vg83
K7AntiVirusTrojan ( 00515ebd1 )
AlibabaTrojan:Win32/Skeeyah.5d1c7831
K7GWTrojan ( 00515ebd1 )
VirITTrojan.Win32.MulDrop7.CDPI
SymantecTrojan.Glupteba
ESET-NOD32a variant of WinGo/RanumBot.H
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Scar.qblo
BitDefenderGen:Variant.Ser.Ursu.17457
NANO-AntivirusTrojan.Win32.Scar.exnywe
RisingTrojan.Generic@AI.100 (RDML:iH0NMs4lFhcR8PKuhUnZag)
SophosMal/Generic-R
F-SecureHeuristic.HEUR/AGEN.1314276
DrWebTrojan.MulDrop7.37578
VIPREGen:Variant.Ser.Ursu.17457
TrendMicroTROJ_FRS.0NA103E820
EmsisoftGen:Variant.Ser.Ursu.17457 (B)
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.bfuyf
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1314276
Antiy-AVLTrojan/Win32.Scar
Kingsoftmalware.kb.a.961
MicrosoftTrojan:Win32/Skeeyah.A!bit
XcitiumMalware@#1syanpea2fpl7
ArcabitTrojan.Ser.Ursu.D4431
ViRobotTrojan.Win32.Z.Scar.3315200
ZoneAlarmTrojan.Win32.Scar.qblo
GDataGen:Variant.Ser.Ursu.17457
GoogleDetected
AhnLab-V3Trojan/Win32.Skeeyah.C2128299
McAfeeArtemis!922C52DEE4BF
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32Trojan.MulDrop
MalwarebytesMalware.AI.3925551196
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.0NA103E820
TencentMalware.Win32.Gencirc.13b18027
YandexTrojan.Scar!yv2dmLv2d4Q
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
alibabacloudTrojan:Multi/RanumBot.H

How to remove Malware.AI.3925551196?

Malware.AI.3925551196 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment