Malware

Malware.AI.3930375053 malicious file

Malware Removal

The Malware.AI.3930375053 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3930375053 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Malware.AI.3930375053?


File Info:

name: B5E6ADBC293279F3FABA.mlw
path: /opt/CAPEv2/storage/binaries/702ffbdd12d7c77d7df62a230786b73054f2410c2295bb7b6c505852459872fb
crc32: 8273B68C
md5: b5e6adbc293279f3faba5ffbe8ec604b
sha1: 8eae37d35049f3264d8106b4d94b0d27f137ce4a
sha256: 702ffbdd12d7c77d7df62a230786b73054f2410c2295bb7b6c505852459872fb
sha512: 2152c7a9541a9a6f013cd03f45026c86165b761c0d56fea787d6624b87d1ec12a7f05bd9c8b9fcba4a01ae2474603ceb86b45c00c3d355e2bd7cb2a9072f5b30
ssdeep: 49152:4UiTD8W2a+4EZ3p/CagBFT2uvRGxHIR3BL:UTe95ZYaMZGJWL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CB5AE11BBD1C03AE2B312728ABDA26E866CBB70172455C763C80E6E5F755E2FD35213
sha3_384: 7124b37a07e8677db7cadc030130f23ef9f0de0654f1cc6cbc2f37754edf95eaf7f603acabeaa1c3ae8ed157559979aa
ep_bytes: e82c6d0100e989feffff8bff558bec51
timestamp: 2017-10-09 05:50:31

Version Info:

CompanyName: GeekZip
FileDescription: 极客压缩安装程序
FileVersion: 1.0.0.4
InternalName: 极客压缩安装程序
LegalCopyright: Copyright (C) 2017
OriginalFilename: GeekZip
ProductName: GeekZip
ProductVersion: 1.0.0.4
Translation: 0x0804 0x04b0

Malware.AI.3930375053 also known as:

BkavW32.AIDetect.malware2
AVGWin32:Malware-gen
MicroWorld-eScanTrojan.GenericKD.48872108
FireEyeGeneric.mg.b5e6adbc293279f3
McAfeeArtemis!B5E6ADBC2932
ZillyaTrojan.GenericKD.Win32.110734
SangforVirus.Win32.Save.a
Cybereasonmalicious.c29327
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Chindo.AD
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Malware.Chindo-9811086-0
KasperskyHEUR:Trojan-Downloader.Win32.Chindo.vho
BitDefenderTrojan.GenericKD.48872108
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.120db41c
Ad-AwareTrojan.GenericKD.48872108
EmsisoftTrojan.GenericKD.48872108 (B)
VIPRETrojan.GenericKD.48872108
McAfee-GW-EditionBehavesLike.Win32.BadFile.vh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.48872108
JiangminTrojanDownloader.Chindo.eo
AviraHEUR/AGEN.1238343
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.47F6
ArcabitTrojan.Generic.D2E9BAAC
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GoogleDetected
Acronissuspicious
ALYacTrojan.GenericKD.48872108
MalwarebytesMalware.AI.3930375053
RisingAdware.Agent!1.CF1C (CLASSIC)
IkarusTrojan-Downloader.Win32.Chindo
FortinetW32/Chindo.N!tr.dldr
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.3930375053?

Malware.AI.3930375053 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment