Malware

Should I remove “Malware.AI.3956779176”?

Malware Removal

The Malware.AI.3956779176 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3956779176 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3956779176?


File Info:

name: DC9C79190E3445E44535.mlw
path: /opt/CAPEv2/storage/binaries/ec3ced2922189ef1810c5d96cc18a6ef6a4bdfd45e2061cf9c1b3a7db3eb1b37
crc32: 28CD9194
md5: dc9c79190e3445e4453568da5c9f1879
sha1: aea287f2bf7c294038ad2b8e98017c1b85127b00
sha256: ec3ced2922189ef1810c5d96cc18a6ef6a4bdfd45e2061cf9c1b3a7db3eb1b37
sha512: fe766f20e930f14ee57fc9dd086b3d882edadea03fe1ce81ab69cec39835a25ed7c0cb303cd6f1539b32b23cb988f8bd198b9646eb4e3be156e56a16e383871b
ssdeep: 49152:Shbyw1OqFn68Im1CMQ7bjI8UEra+rBtiziwDYnB/8/KJyx8YMADGgqprPiiioOxe:YG4568+MQ7I8/raEj0iEYnBU/KJyx7M1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141C533C3F312E834E01259724B4C6CD6625BB10A5E9E39977D0BC00F3FB7B505AEA56A
sha3_384: 23e1431d0fe5ade4ba5d13f675be19b3f408bdfc11a567fce49a570720254227ecae5444ffbf37594b93a36c4a7d5e15
ep_bytes: 60be00507d008dbe00c0c2ffc787a8f0
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.1.4.256
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x040c 0x04e4

Malware.AI.3956779176 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
MicroWorld-eScanTrojan.GenericKD.68967913
FireEyeTrojan.GenericKD.68967913
SkyhighBehavesLike.Win32.Dropper.vc
McAfeeArtemis!DC9C79190E34
Cylanceunsafe
ZillyaTrojan.Ekstak.Win32.73875
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
ArcabitTrojan.Generic.D41C5DE9
KasperskyVHO:Trojan.Win32.Ekstak.gen
BitDefenderTrojan.GenericKD.68967913
RisingTrojan.Ekstak!8.EB77 (CLOUD)
EmsisoftTrojan.GenericKD.68967913 (B)
VIPRETrojan.GenericKD.68967913
SophosMal/Generic-S
Antiy-AVLTrojan/Win32.Ekstak
ZoneAlarmVHO:Trojan.Win32.Ekstak.gen
GDataTrojan.GenericKD.68967913
ALYacTrojan.GenericKD.68967913
MAXmalware (ai score=89)
MalwarebytesMalware.AI.3956779176
TrendMicro-HouseCallTROJ_GEN.R002H09I123
MaxSecureTrojan.Malware.73555928.susgen
DeepInstinctMALICIOUS

How to remove Malware.AI.3956779176?

Malware.AI.3956779176 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment