Malware

About “Malware.AI.3952913491” infection

Malware Removal

The Malware.AI.3952913491 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3952913491 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3952913491?


File Info:

name: 68676D2534BEA1686285.mlw
path: /opt/CAPEv2/storage/binaries/3896a2bd58df26f235cbec29a63ac84a30ca26fd93e6590fd010daea66efc458
crc32: A5FA0DB4
md5: 68676d2534bea168628530c037c44cdf
sha1: 90536ebfd266fc9b3f7bb83cdd2fd336c23f5bce
sha256: 3896a2bd58df26f235cbec29a63ac84a30ca26fd93e6590fd010daea66efc458
sha512: 9dfa3cf9e204b21bcdfc079a28bd44fb091a79e3a10492d96d7236c476a90e404a3e95d92cc9e35cb39b29f5fe68e07081cfb8220b9c487561b4fb37afa00817
ssdeep: 12288:XQHB32Uou0EterSIdWrSFBkTl8FrEh2azX/z:A4Xu0EteWI+SFBG03evz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117C4699CFD089B07CA7F29393771E8A971531C87768242F163C9FE2B3862D0E565892D
sha3_384: 1aa5eb1a0babd60f6bc6f95dcf054d53d92c7a6a2fc26579c3e46a16e4033e458d9cca21497d40419899507faeb982ac
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2023-07-08 05:25:30

Version Info:

FileVersion: 1.1.37.01c
ProductVersion: 1.1.37.01c
Translation: 0x0409 0x04b0

Malware.AI.3952913491 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Generic.hc
MalwarebytesMalware.AI.3952913491
CrowdStrikewin/malicious_confidence_70% (D)
APEXMalicious
SophosML/PE-A
Antiy-AVLTrojan/Win32.Possiblethreat
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.fd266f
DeepInstinctMALICIOUS

How to remove Malware.AI.3952913491?

Malware.AI.3952913491 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment