Malware

What is “Malware.AI.957915277”?

Malware Removal

The Malware.AI.957915277 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.957915277 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.957915277?


File Info:

name: 3A611CC538A14F632342.mlw
path: /opt/CAPEv2/storage/binaries/9b96baa094e7414ce32809fc06eae32b35cb9171e1c6d3d7b727c753583dbf9c
crc32: C2433DFD
md5: 3a611cc538a14f632342770391146060
sha1: 77c59a423c612bd302b210a93580ff1bca34b9fd
sha256: 9b96baa094e7414ce32809fc06eae32b35cb9171e1c6d3d7b727c753583dbf9c
sha512: 6c5ff432db5051ab54502332a453139281ece1c57cafe585948fd9c16a6f68ca8841cf6ca48e81eacdaa14dc1b92670966e2a60d6173dce90e41ae65b75f998f
ssdeep: 6144:TwmOEAf+wu+TdS95INIJzovOcb7AOgvhK:TpO/fc+U95IGmvOcX1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172156D137CCD9AF8D3542C7C0C85EC2C975AB39B61264DC5F6D8471A4FBA10B98878BA
sha3_384: 6256e9e338878e1ffdea3cb260fa66d861d975d9cef98e8deeb11e6c504371366eaa43b6adb8a7cd1a672446a5f3bc44
ep_bytes: 6a6068484f4a00e80e5b0000bf940000
timestamp: 2013-07-03 20:41:28

Version Info:

0: [No Data]

Malware.AI.957915277 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lIKC
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.45299
ClamAVWin.Trojan.Agent-1300476
CAT-QuickHealTrojanDropper.Vundo.AB3
ALYacGen:Variant.Jaik.45299
MalwarebytesMalware.AI.957915277
ZillyaTrojan.Kryptik.Win32.436417
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.23c612
VirITTrojan.Win32.Crypt2.BXJU
CyrenW32/Agent.AEB.gen!Eldorado
SymantecPacked.Generic.455
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BESX
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Jaik.45299
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Rootkit-gen [Rtk]
TencentMalware.Win32.Gencirc.10b88cab
EmsisoftGen:Variant.Jaik.45299 (B)
F-SecureTrojan.TR/Vundo.Gen
DrWebTrojan.WinSpy.1014
VIPREGen:Variant.Jaik.45299
McAfee-GW-EditionObfuscated-FAKJ!hb
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.3a611cc538a14f63
SophosMal/EncPk-ACWD
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Jaik.45299
JiangminTrojan/Generic.azpey
WebrootW32.Malware.Gen
AviraTR/Vundo.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.ZPACK.BCDI@54sthp
ArcabitTrojan.Jaik.DB0F3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vundo
GoogleDetected
AhnLab-V3Trojan/Win32.Pirminay.R89192
McAfeeObfuscated-FAKJ!hb
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Vundo!8.4FC (TFE:5:xAlv26wCjkJ)
IkarusTrojan.Win32.Pirminay
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ponmocup.GA!tr
BitDefenderThetaGen:NN.ZexaF.36738.3mX@a01MzMg
AVGWin32:Rootkit-gen [Rtk]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.957915277?

Malware.AI.957915277 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment