Malware

How to remove “Malware.AI.3975371631”?

Malware Removal

The Malware.AI.3975371631 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3975371631 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3975371631?


File Info:

name: 38F873761B7379E7D951.mlw
path: /opt/CAPEv2/storage/binaries/e7505d8134441862f2b684d46899dfc15bc6bbb9b7bee08711d67d695481dfa2
crc32: 4E18C55C
md5: 38f873761b7379e7d9516ad784d2ef35
sha1: bb0086473d0d2496dd1b7a6c35205ff1836cac30
sha256: e7505d8134441862f2b684d46899dfc15bc6bbb9b7bee08711d67d695481dfa2
sha512: dfb891c76c7c2ea75fa36a6c66d173d4219c6a89ce0e801426b1c70a981627c4fd5a444877748f6f6faec377e2b83488508a2ee85424e3de9f9bbd60b2641cf2
ssdeep: 6144:Ip9HU3S0GG6iffA9PsR+gpd1fUZ7oCSr/eu+zYJfnWV33Nnhr:iW3S0G1Aoo+gpjfUZMCl3/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166F48C31C282C41DD4F342FFD3A32B2D0DD4BF525667239B7AD44E495A70AA8EA5360B
sha3_384: fe1a5345cf3aa3b7967b1ad319f754bbd8901ccb04d0095c6e402c9720da187ae651c37be16a069a35ae0301fdd6d989
ep_bytes: 558bec6aff68402f470068808f440064
timestamp: 1998-05-14 02:32:54

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Notepad application file
FileVersion: 4.10.1998
InternalName: Notepad
LegalCopyright: Copyright (C) Microsoft Corp. 1991-1998
OriginalFilename: NOTEPAD.EXE
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 4.10.1998
Translation: 0x0804 0x03a8

Malware.AI.3975371631 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.38f873761b7379e7
SkyhighBehavesLike.Win32.Generic.bm
SangforTrojan.Win32.Agent.V3k3
Cybereasonmalicious.73d0d2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.6395774-1
NANO-AntivirusTrojan.Win32.Buzus.cvlfbl
AvastWin32:Malware-gen
RisingTrojan.Generic@AI.91 (RDML:18HHrmcxMTDWnm269bpI3Q)
Trapminemalicious.moderate.ml.score
IkarusBackdoor.Win32.SuspectCRC
VaristW32/Worm.RDYQ-1217
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
McAfeeArtemis!38F873761B73
MalwarebytesMalware.AI.3975371631
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3975371631?

Malware.AI.3975371631 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment