Malware

Should I remove “Malware.AI.3946685313”?

Malware Removal

The Malware.AI.3946685313 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3946685313 virus can do?

  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.3946685313?


File Info:

name: 4F1817C6890A600FFD93.mlw
path: /opt/CAPEv2/storage/binaries/3c92750267f892edd84243b2d4399ed4def6cd6ec24979ec3cebda84a98b43c6
crc32: C6144434
md5: 4f1817c6890a600ffd93953ff6d317fc
sha1: b56fe2100de188e29534b1ba80f801d99c0c47b2
sha256: 3c92750267f892edd84243b2d4399ed4def6cd6ec24979ec3cebda84a98b43c6
sha512: 49954516b6ac6584ba5332b9d0ea569cd55701aa669d8dc4a0558d3366e150cd9a273d7d2d00430fd9228ff0f4b4918b420cff521d689ad20516c82e6b431e4d
ssdeep: 12288:3WYqnwTrEv888888888888W88888888888ZvOrU5X2iA6q49/RxuSS1/Df:GYqwTY3WazA6rzxuSS1/j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EC4F103A3C30872F47A1DB9C855E188BC2AB9B82ED4602B7CF4DD4E45BD3D21C799A5
sha3_384: 6cb1a702bcc29f7ea0f4d4762333ef97cb55ca86ff968907a4e73be1c39125ae51c3f28975b5f297f342a63a35a56b03
ep_bytes: 558becb9080000006a006a004975f953
timestamp: 2013-10-31 10:13:11

Version Info:

CompanyName: IObit
FileDescription: Driver Backup Package
FileVersion: 1.1.0.0
InternalName: UpdateDB
LegalCopyright: Copyright© 2013 IObit. All Rights Reserved.
LegalTrademarks: IObit
OriginalFilename: SfxStub.exe
ProductName: Driver Booster
ProductVersion: 1.1.0.0
Comments: Driver Database Updater
Translation: 0x0409 0x04e4

Malware.AI.3946685313 also known as:

BkavW32.AIDetectMalware
CAT-QuickHealTrojan.GenericPMF.S2873331
McAfeeRDN/Generic.dx
MalwarebytesMalware.AI.3946685313
SangforTrojan.Win32.Save.a
AlibabaTrojanDropper:Win32/Jacard.7a13dd7d
BitDefenderThetaAI:Packer.759C860817
CyrenW32/Jacard.A.gen!Eldorado
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Dropper.Genericrxjd-9884871-0
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Yarwi
JiangminPacked.Dico.dxt
GoogleDetected
CynetMalicious (score: 100)
VBA32Trojan.Wacatac
TrendMicro-HouseCallTROJ_GEN.R002H0CE623
RisingTrojan.Generic@AI.100 (RDML:WA60viiEHLOgZHv0HXEn6g)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.YARW!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.3946685313?

Malware.AI.3946685313 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment