Malware

Malware.AI.3962335529 removal

Malware Removal

The Malware.AI.3962335529 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3962335529 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.3962335529?


File Info:

name: 482B7C9E3A4D7800B558.mlw
path: /opt/CAPEv2/storage/binaries/223804ec09c6feee191239f0f069b319e983203f0e2e0dc4a5fb09cbab3b7ac0
crc32: BC118ECA
md5: 482b7c9e3a4d7800b558c00d8233e480
sha1: c0e9fc8f679329f507060e681b8b95e56f64c3a9
sha256: 223804ec09c6feee191239f0f069b319e983203f0e2e0dc4a5fb09cbab3b7ac0
sha512: b7a0914b075b01051a2892da6673a07a629eff8d6f56f0269b71e869dc2db9fa919c68e7fe84e83f752ce7e957e24ca7082999073fcf7eedb052e6bcdeff72e1
ssdeep: 192:HnjqMhixibiffPPcM/WjmlwBfSnzGfuUTzTz:HREOyfPPXvw4abHTz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14832623C6ED92AB7E3B3C6B6C6F646C6BD65B02239129C0E40DA03450D13F57ADD291E
sha3_384: 6211a4c5e94a68b3ccb70d97e2f4fd2582c6e6d0775378aee598fbc18e56a8b411164c7179194dc052d504c846060cee
ep_bytes: 60be008040008dbe0090ffff57eb0b90
timestamp: 2013-09-18 07:50:14

Version Info:

0: [No Data]

Malware.AI.3962335529 also known as:

BkavW32.AIDetectMalware
AVGWin32:Downloader-WID [Trj]
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanGen:Variant.Barys.379359
FireEyeGeneric.mg.482b7c9e3a4d7800
SkyhighBehavesLike.Win32.Generic.lt
McAfeeDownloader-FBVZ!E1F4A0D9622E
MalwarebytesMalware.AI.3962335529
VIPREGen:Variant.Barys.379359
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.e3a4d7
BitDefenderThetaGen:NN.ZexaF.36802.amHfaS6Scvei
SymantecDownloader.Upatre!gm
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.379359
AvastWin32:Downloader-WID [Trj]
SophosTroj/Upatre-YW
F-SecureTrojan.TR/Downloader.Gen
BaiduWin32.Trojan-Downloader.Waski.k
ZillyaDownloader.Waski.Win32.90636
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Barys.379359 (B)
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan.Generic.aajcx
VaristW32/Agent.INH.gen!Eldorado
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.b.998
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Small.CDC@8mzsfr
ArcabitTrojan.Barys.D5C9DF
ZoneAlarmVHO:Trojan-Downloader.Win32.Convagent.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win.Upatre.C5600603
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Barys.379359
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!BNPu10462mc
SentinelOneStatic AI – Malicious PE
FortinetW32/Dloader.ADC!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3962335529?

Malware.AI.3962335529 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment