Malware

Malware.AI.3964835239 information

Malware Removal

The Malware.AI.3964835239 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3964835239 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3964835239?


File Info:

name: A7EDB5BCF987C3F86CB6.mlw
path: /opt/CAPEv2/storage/binaries/724ce4daa600968ded2b9d839b00d6c5f443675a78e6d443d80cde594e38ee8c
crc32: 3B612254
md5: a7edb5bcf987c3f86cb64794fa8c686d
sha1: eb61c74042476fdf3f779244539ce09eda1ec2d9
sha256: 724ce4daa600968ded2b9d839b00d6c5f443675a78e6d443d80cde594e38ee8c
sha512: 6434a68f9b7d618aefabf324e702e54f5a8dfcb7a6c4b86bca42cb7ee3402b2f499c29cf2fb2f8e0b3317029742a309664b225955feb8a447e89f649a9cf4bd8
ssdeep: 6144:udPpa8QFXAGuIDhYBHHyLu09BamrxZbtougM4KM:8paTAkDaByL/98mdNt34t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F241282B6900875E82F0CBAC95BE0225B4FE555887C458F4D6CDA064F5BE37428BFE7
sha3_384: 85076515b4e3e943d4f801390c42a947bc47d036549bfd4e5bd5c6dc9d272b884ad38b72f2961aaa403e9091acb291aa
ep_bytes: 60be00b045008dbe0060faff57eb0b90
timestamp: 2015-08-01 19:56:55

Version Info:

Comments:
CompanyName:
FileDescription: AAAA
FileVersion: 0, 0, 0, 0
InternalName:
LegalCopyright: 2021
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName:
ProductVersion: 0, 0, 0, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.3964835239 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Bozv.4!c
Elasticmalicious (moderate confidence)
DrWebTrojan.KillProc.36698
MicroWorld-eScanTrojan.Agent.BOZV
FireEyeGeneric.mg.a7edb5bcf987c3f8
CAT-QuickHealTrojan.MauvaiseRI.S5249686
ALYacTrojan.Agent.BOZV
Cylanceunsafe
VIPRETrojan.Agent.BOZV
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Agent.BOZV
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.cf987c
BitDefenderThetaGen:NN.ZexaF.36196.nmLfaWZ01Wfi
SymantecSMG.Heur!gen
ESET-NOD32a variant of Generik.VNPVTL
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.xafihr
AlibabaTrojan:Win32/Bulta.dcfbf3da
NANO-AntivirusTrojan.Win32.Blocker.dzaanf
RisingRansom.Blocker!8.12A (CLOUD)
SophosMal/Behav-039
F-SecureHeuristic.HEUR/AGEN.1322255
ZillyaTrojan.Blocker.Win32.35350
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Agent.BOZV (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BOZV
JiangminTrojan/Blocker.ozj
AviraHEUR/AGEN.1322255
MAXmalware (ai score=80)
Antiy-AVLTrojan[Ransom]/Win32.Blocker
ArcabitTrojan.Agent.BOZV
ZoneAlarmTrojan.Win32.Agent.xafihr
MicrosoftPWS:Win32/Zbot!ml
GoogleDetected
AhnLab-V3Malware/Gen.RL_Generic.R288671
McAfeeGenericRXAA-AA!A7EDB5BCF987
DeepInstinctMALICIOUS
VBA32Trojan.KillProc
MalwarebytesMalware.AI.3964835239
PandaTrj/Agent.OOW
TencentWin32.Trojan.Agent.Kqil
IkarusTrojan.Backdoor.Agent
FortinetW32/Generic!tr.dldr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.3964835239?

Malware.AI.3964835239 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment