Malware

Should I remove “Malware.AI.145341988”?

Malware Removal

The Malware.AI.145341988 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.145341988 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.145341988?


File Info:

name: 4D712047F4680D1714EA.mlw
path: /opt/CAPEv2/storage/binaries/4b21d28faa92aa36c6ea1a83376211d28097fa12ed0d8c6522c6b7e759e665b7
crc32: 1DB7C028
md5: 4d712047f4680d1714ea267bbb4d9cf4
sha1: 8649feac71f01a75acccf23fb9c3b2b3918d2609
sha256: 4b21d28faa92aa36c6ea1a83376211d28097fa12ed0d8c6522c6b7e759e665b7
sha512: 915e36c5d94e83271e58c7e8e91cc5f86b3af3a750b3f99b7cc78fb9dce138997c17c2b02da9ffb4a89117c5d97597bea0972366df2b522bff83aa9644dcdbd9
ssdeep: 12288:o6SgZiHzTFhG5ZjyZcme6zc7EFFqDDscS:o6SgqTDMZjyZPeX8Fq0z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D940216FB9284F3C4404630455E6ABBE23AF7051770938E9BAA5DEB7CF5143780AEC6
sha3_384: ef40fb7c8dd99cced8f91f46ef19716e38e0ffb32fd98b62f9e9f72f63afa5e12c982ed21046e615ac7186fd4c6a315a
ep_bytes: 60be006040008dbe00b0ffff5783cdff
timestamp: 2009-09-28 09:53:34

Version Info:

0: [No Data]

Malware.AI.145341988 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Magania.kZOx
Elasticmalicious (moderate confidence)
MicroWorld-eScanGeneric.Onlinegames.14.6C09EA76
FireEyeGeneric.mg.4d712047f4680d17
CAT-QuickHealTrojan.Magania.20501
SkyhighBehavesLike.Win32.Generic.gc
ALYacGeneric.Onlinegames.14.6C09EA76
MalwarebytesMalware.AI.145341988
VIPREGeneric.Onlinegames.14.6C09EA76
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 000d26221 )
BitDefenderGeneric.Onlinegames.14.6C09EA76
K7GWTrojan ( 000d26221 )
Cybereasonmalicious.c71f01
ArcabitGeneric.Onlinegames.14.6C09EA76
BaiduWin32.Trojan-PSW.OLGames.ab
VirITTrojan.Win32.Proxy.AIQR
SymantecInfostealer.Gampass
ESET-NOD32Win32/PSW.OnLineGames.NRD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Magania-9805469-0
KasperskyTrojan-GameThief.Win32.Magania.cmgm
AlibabaTrojanPSW:Win32/OnLineGames.b94fd871
NANO-AntivirusTrojan.Win32.Wsgame.bbsgwr
ViRobotTrojan.Win32.PSWIGames.29200.E
RisingStealer.OnlineGames!1.9ECD (CLASSIC)
EmsisoftGeneric.Onlinegames.14.6C09EA76 (B)
F-SecureHeuristic.HEUR/AGEN.1323236
DrWebTrojan.PWS.Wsgame.13178
ZillyaTrojan.OnLineGames.Win32.35696
TrendMicroTSPY_LOLYDA.SMC
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.OnLineGames.bgvo
VaristW32/OnlineGames.CA.gen!Eldorado
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[GameThief]/Win32.Magania
Kingsoftmalware.kb.b.992
XcitiumTrojWare.Win32.PSW.OnLineGames.~ASAA@u59wd
MicrosoftTrojan:Win32/Vindor!pz
ZoneAlarmTrojan-GameThief.Win32.Magania.cmgm
GDataGeneric.Onlinegames.14.6C09EA76
GoogleDetected
AhnLab-V3Trojan/Win32.OnlineGameHack.R2006
Acronissuspicious
McAfeeGeneric Dropper.ajh
DeepInstinctMALICIOUS
VBA32BScope.Trojan-Dropper.Tabloid.4
Cylanceunsafe
PandaTrj/Lineage.LCC
ZonerTrojan.Win32.36572
TrendMicro-HouseCallTSPY_LOLYDA.SMC
TencentTrojan.Win32.OnlineGames.tbn
YandexTrojan.GenAsa!0IedP0WHKkw
IkarusTrojan-GameThief.Win32.Magania
MaxSecureTrojan.Malware.22645.susgen
FortinetW32/BanLoader.AAAM!tr
BitDefenderThetaAI:Packer.15CAFC331E
AVGWin32:Agent-ACMH [Drp]
AvastWin32:Agent-ACMH [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.145341988?

Malware.AI.145341988 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment