Malware

Malware.AI.3997535622 removal instruction

Malware Removal

The Malware.AI.3997535622 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3997535622 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • A scripting utility was executed
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Suspicious wmic.exe use was detected

How to determine Malware.AI.3997535622?


File Info:

name: 3E28238606A99A06F26B.mlw
path: /opt/CAPEv2/storage/binaries/1122fb5eca3b938b453f9ddc863792b11f76837828df6d6d1283bfbf2a670b76
crc32: 858AF35E
md5: 3e28238606a99a06f26b7a2ab28afb11
sha1: 2cde40948fd8af5585c31cc0b7353c10cb57fdf0
sha256: 1122fb5eca3b938b453f9ddc863792b11f76837828df6d6d1283bfbf2a670b76
sha512: 3e7121e07ac7b793aeb1eef552b9ce17a8786fa2f12459be51c2ad793167ee5e452d20fb8a933b9a6cda31c1709f6a1ae0529089ef76be90b1b081c487b885cb
ssdeep: 12288:xAHiKgHyfT65S65VGxoTwEzr9VhURFVBc3nkUL:xACKTfTkzuuTXvhU1oh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB941211FBF4C5F6D06B11B059942F56847AFEB5070888E397A4BC0A6F706C6E72E24B
sha3_384: 400b34ad3b63a19d3071cbb4600d37a1460591b25a09a80168d992d46fb3c96db2285247d48d9733cc583d9a33018fa8
ep_bytes: 558bec6aff68505e410068602f410064
timestamp: 2012-12-30 08:49:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: https://www.microsoft.com/uk-ua/
FileVersion: 6.3.9600.16384
InternalName: PowerModule
LegalCopyright: Copyright © 2005-2016 Microsoft Corporation
ProductName: PowerModule.exe (ntuser.pol)
PrivateBuild: December 30, 2015
ProductVersion: 6.3.9600.16384
Translation: 0x0000 0x04b0

Malware.AI.3997535622 also known as:

CynetMalicious (score: 99)
FireEyeGen:Variant.Ser.Ursu.15688
McAfeeGenericR-POS!3E28238606A9
K7AntiVirusTrojan ( 0012a2041 )
K7GWTrojan ( 0012a2041 )
Cybereasonmalicious.606a99
CyrenBAT/Agent.AJX
Elasticmalicious (high confidence)
ESET-NOD32BAT/Agent.NEH
ClamAVWin.Malware.Pterodo-9849653-0
KasperskyWorm.BAT.Agent.dh
BitDefenderGen:Variant.Ser.Ursu.15688
MicroWorld-eScanGen:Variant.Ser.Ursu.15688
AvastBV:Gamaredon-D [Apt]
Ad-AwareGen:Variant.Ser.Ursu.15688
EmsisoftGen:Variant.Ser.Ursu.15688 (B)
ComodoMalware@#g635xqu9c8pb
F-SecureHeuristic.HEUR/AGEN.1227137
VIPREGen:Variant.Ser.Ursu.15688
McAfee-GW-EditionGenericR-POS!3E28238606A9
IkarusWorm.BAT.Agent
AviraHEUR/AGEN.1227137
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ser.Ursu.D3D48
ZoneAlarmWorm.BAT.Agent.dh
GDataBAT.Trojan.Agent.23SWCX
GoogleDetected
ALYacGen:Variant.Ser.Ursu.15688
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3997535622
AVGBV:Gamaredon-D [Apt]

How to remove Malware.AI.3997535622?

Malware.AI.3997535622 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment