Malware

Malware.AI.3952822932 removal guide

Malware Removal

The Malware.AI.3952822932 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3952822932 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family
  • Anomalous binary characteristics

How to determine Malware.AI.3952822932?


File Info:

name: 278773EE8E7651A71493.mlw
path: /opt/CAPEv2/storage/binaries/77f35b324e229bb43af51e159b495ba206d6ab2c3436d39a904f799d651d58b6
crc32: 2F0DA691
md5: 278773ee8e7651a714933d379c857bbc
sha1: 34cd208b09669d5d6568e494498e0c79f45e7752
sha256: 77f35b324e229bb43af51e159b495ba206d6ab2c3436d39a904f799d651d58b6
sha512: 58afca836767a1981e9584d6c2d15d6cfb05ad8996da7f1f456bf2666ce5db708ec99378dec4233cab669c3ee1eb7c6e6e5688cf0e4737e32a14a992c5ba65a9
ssdeep: 12288:Zprh9CXqVYME9ol1oLoLCRiVyQxqiGq2Y7fmtsuuLbOyfFzNoZ4b+WvK:ZpGaVLAjo7Vy9iG4msFbPFb+WS
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18BE433F308B46331E0F1CB71BA227DEE3325ABF106A4657F716C9EB69964C8228D55D0
sha3_384: 6b5789ac8cbf7ec5e4a556b70080c5fc84a6b8f0b3ff5a326a5a97bbe9a03ed720875953a49b1708cc49099af018c6a3
ep_bytes: 60e9aee1feff600fbeea8b6c24346818
timestamp: 2017-05-20 03:20:22

Version Info:

0: [No Data]

Malware.AI.3952822932 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.56963
ClamAVWin.Malware.Generickdz-9774373-0
FireEyeGeneric.mg.278773ee8e7651a7
McAfeeGenericRXCV-CP!278773EE8E76
CylanceUnsafe
VIPRETrojan.GenericKDZ.56963
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Agent.ENU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.FB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Sdum.gen
BitDefenderTrojan.GenericKDZ.56963
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKDZ.56963
SophosMal/Generic-S
ComodoVirus.Win32.Virut.CE@1fhkga
F-SecureHeuristic.HEUR/AGEN.1225299
McAfee-GW-EditionBehavesLike.Win32.Injector.bc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.56963 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.56963
JiangminTrojan.Sdum.ac
AviraHEUR/AGEN.1225299
ArcabitTrojan.Generic.DDE83
ZoneAlarmHEUR:Trojan.Win32.Sdum.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2333637
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34698.SyW@a8wt3Kmi
ALYacTrojan.GenericKDZ.56963
MAXmalware (ai score=86)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.3952822932
RisingTrojan.Generic@AI.92 (RDMK:qB0I2nYPyqI5iQK905SEaA)
YandexTrojan.GenAsa!igJrG5Gbqu4
IkarusTrojan.Win32.VMProtect
MaxSecureTrojan.Malware.10994207.susgen
FortinetW32/VMProtect.FB!tr
AVGWin32:Malware-gen
Cybereasonmalicious.e8e765
PandaTrj/Genetic.gen

How to remove Malware.AI.3952822932?

Malware.AI.3952822932 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment