Malware

Malware.AI.3930393434 malicious file

Malware Removal

The Malware.AI.3930393434 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3930393434 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects Bochs through the presence of a registry key

How to determine Malware.AI.3930393434?


File Info:

name: DD184C516012358F3458.mlw
path: /opt/CAPEv2/storage/binaries/1c41f57598db31f3064f25356569367fc1a1d1d9493b918bf5b1e235949c1f41
crc32: 2A4FB2F9
md5: dd184c516012358f345818ffa91d3fba
sha1: aa55cccc953e7e098051c2e30cb1c467723a9252
sha256: 1c41f57598db31f3064f25356569367fc1a1d1d9493b918bf5b1e235949c1f41
sha512: 4a0128889ab11086d30fb174ec3d86b63072ab681a83a419af424d28a696fc703188bfd9f0578c61c62b0cd9168123d8ed7a53917c9ad5690b84a36f0b2cf61a
ssdeep: 49152:lxd9b+74yenku3/xi/17VoWmBzGqzJfWv1vN4x8uPyMsnPyBIUeJ:Tb+7L4g/15EzHZ8Wp5qN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155C5339A16DCC495E10A0BF6C835BD17EB7B2C20D722F2CFC398EA6B3611993815C759
sha3_384: 4715d456651a2b3a26e4e015b7b60d023524157080e216382d799df876adde3559ab75a6264d8de479cf4d082e52d364
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:23

Version Info:

0: [No Data]

Malware.AI.3930393434 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45021213
FireEyeTrojan.GenericKD.45021213
ALYacTrojan.GenericKD.45021213
CylanceUnsafe
SangforSuspicious.Win32.Evo.gen
K7AntiVirusTrojan ( 00564e581 )
BitDefenderTrojan.GenericKD.45021213
K7GWTrojan ( 00564e581 )
Cybereasonmalicious.160123
BitDefenderThetaGen:NN.ZexaE.34742.UuW@a8Kx3zbj
CyrenW32/Agent.DRX.gen!Eldorado
ESET-NOD32a variant of Win32/Agent.UEL
Paloaltogeneric.ml
ClamAVWin.Malware.GoldenSpy-9867222-1
AlibabaTrojan:Win32/Generic.48fdd557
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareTrojan.GenericKD.45021213
EmsisoftTrojan.GenericKD.45021213 (B)
ComodoMalware@#2t09z0k3i5drt
TrendMicroTROJ_GEN.R002C0PLM21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Generic.hdqnf
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.GenericKD.45021213
CynetMalicious (score: 100)
McAfeeArtemis!DD184C516012
MAXmalware (ai score=83)
VBA32BScope.Trojan.Agentb
MalwarebytesMalware.AI.3930393434
YandexTrojan.Agent!NmIpxHvfuUY
FortinetW32/Agent.UEL!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3930393434?

Malware.AI.3930393434 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment