Malware

Malware.AI.3957572015 removal

Malware Removal

The Malware.AI.3957572015 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3957572015 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Malware.AI.3957572015?


File Info:

name: 1C1B1353EBBD83D2F0DF.mlw
path: /opt/CAPEv2/storage/binaries/a0bc7bbe02d80c0f2d72b6bc09c590e2ef954d5d913e49576e21681f6af29845
crc32: 90B1F66B
md5: 1c1b1353ebbd83d2f0df5be0485e5ee4
sha1: 1620290d189860c8d39929190f0afa4c0c760d0e
sha256: a0bc7bbe02d80c0f2d72b6bc09c590e2ef954d5d913e49576e21681f6af29845
sha512: 70a8ccbc9a3f2fb5cd496bec15ce4211eefcaab4a8037f7c914916136642c7ce4931f85916637b45bd3dcddc423b89f72d6a0e34c2b2a6a73ab1e574abb007b4
ssdeep: 6144:5d93ZBZMbqYgomHBCFF0ofBP3uCrzpZzEsD0t6:5r3ZBIRbFiofBPuCrzLEsz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18834F106B7C281F2D4414B70547D63B9E638FF01BA70D29FCB9B0E2D6C76502A55AB63
sha3_384: 56706135cae69bbba6b662e5bcd86fccf5b45511770614eb57ae812b1aca652141c4a2d3f3a9fe4290b910bc4a288869
ep_bytes: e89f28000050e8832a01000000000090
timestamp: 2006-08-04 18:28:08

Version Info:

0: [No Data]

Malware.AI.3957572015 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanTrojan.ScriptKD.1412
FireEyeTrojan.ScriptKD.1412
CylanceUnsafe
AlibabaTrojanClicker:BAT/Disabler.0f90a40d
Cybereasonmalicious.3ebbd8
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
BitDefenderTrojan.ScriptKD.1412
SophosNirCmd (PUA)
ComodoMalware@#xu20iidljdg2
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.0CBQ13
EmsisoftTrojan.ScriptKD.1412 (B)
WebrootW32.Backdoor.Gen
AviraBAT/Disabler.lkoes
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Disabler.241009
GDataGen:Trojan.FWDisable.aaW@aaaaa
CynetMalicious (score: 99)
McAfeeArtemis!1C1B1353EBBD
MAXmalware (ai score=82)
MalwarebytesMalware.AI.3957572015
TrendMicro-HouseCallTROJ_SPNR.0CBQ13
TencentWin32.Trojan.Spnr.Dxxb
FortinetW32/Disabler.NAK!tr
PandaTrj/OCJ.D

How to remove Malware.AI.3957572015?

Malware.AI.3957572015 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment