Malware

Malware.AI.3945277072 information

Malware Removal

The Malware.AI.3945277072 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3945277072 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3945277072?


File Info:

name: 40E67636502B09BD63A8.mlw
path: /opt/CAPEv2/storage/binaries/f86d3d0b7a6d67ac8c29418c44f844533c6becf4ebe4a0d667ac3ee0626d21fe
crc32: 3A99C08F
md5: 40e67636502b09bd63a8a1a432c619ab
sha1: bee974465abaf0c4d36adf87e387d18486312d0f
sha256: f86d3d0b7a6d67ac8c29418c44f844533c6becf4ebe4a0d667ac3ee0626d21fe
sha512: d1e04b505c8b0ba9025ab1e6f1c42a088975f5e038f62b97593c32d135d20db2458906a859acce7e942ab0432b1545e128f009fb95038366dd9cab8283256f39
ssdeep: 24576:PysPZfZKtiwKX0KarCgQkEaHNYK3e3it/Ta:KsPZfwu0KpgQNag2/m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1858512AEAF40FF1FCC0052B5A415ED7C02812E7C6460CB16AEE97977B5FB261AD35281
sha3_384: f58828f6b7cad45c1fb8161b0ee62397b69a135b658ee6a45c3a39d88a89646c0ed1b8bbd52df5a7dbdb29443a52c127
ep_bytes: 6801605d00e801000000c3c3ce8caf15
timestamp: 2021-12-06 15:35:40

Version Info:

CompanyName: Huge Company
FileDescription: Huge BRUSH
FileVersion: 1.0.0.1
InternalName: HugeBRUSH.exe
LegalCopyright: Copyright 2021
OriginalFilename: HugeBRUSH.exe
ProductName: HugeBRUSH
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Malware.AI.3945277072 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Agent.2!c
MicroWorld-eScanTrojan.GenericKD.38205157
FireEyeTrojan.GenericKD.38205157
ALYacTrojan.GenericKD.38205157
CylanceUnsafe
ZillyaAdware.Agent.Win32.170846
AlibabaAdWare:Win32/Generic.cf791c66
SymantecML.Attribute.HighConfidence
APEXMalicious
Kasperskynot-a-virus:AdWare.Win32.Agent.xxzamb
BitDefenderTrojan.GenericKD.38205157
Ad-AwareTrojan.GenericKD.38205157
SophosGeneric PUA LO (PUA)
DrWebTrojan.Siggen15.65200
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.38205157 (B)
GDataTrojan.GenericKD.38205157
GridinsoftRansom.Win32.Sabsik.sa
CynetMalicious (score: 100)
McAfeeArtemis!40E67636502B
MAXmalware (ai score=81)
VBA32Adware.Convagent
MalwarebytesMalware.AI.3945277072
TrendMicro-HouseCallTROJ_GEN.R067H0CL921
FortinetAdware/OpenSUpdater
BitDefenderThetaGen:NN.ZexaF.34114.UL1aamC0pGni
Cybereasonmalicious.65abaf
PandaTrj/CI.A

How to remove Malware.AI.3945277072?

Malware.AI.3945277072 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment