Malware

Malware.AI.3219852382 removal

Malware Removal

The Malware.AI.3219852382 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3219852382 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3219852382?


File Info:

name: B944F074B1944632A783.mlw
path: /opt/CAPEv2/storage/binaries/3797a4982462923d63cf845dfab74ec5e360d43c7c713c00302363838ce1c5b4
crc32: 06198342
md5: b944f074b1944632a783548575cc9bdb
sha1: 5dc0e00b4db5e5b03ab6675c4f1d847df8f4917d
sha256: 3797a4982462923d63cf845dfab74ec5e360d43c7c713c00302363838ce1c5b4
sha512: dd87f06645b3444330c832b97ecac3cb2793cdb6e81279004c0e8d2f478cade40a9567c8987ff0c7ce70f38657ac5fb5d3a3953abd0c233cf1b96f3ead107f6c
ssdeep: 768:8iH3qBnlQeX/Vi98uMYLu/PZ4FbE9IOTy8EMjtZ+v2MxPha5:RH2mZLx6Ir8EMXS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121133A53D64420A9C6C24731BD16BF674738BE2B953F831DAD6C358ABF74BE18E14A20
sha3_384: 0ba1604e6f88602c0279d1e1affc92ef5e43d0128f294ccdc85bc370a59da892155dd18073f42bf88e2f5b465702450e
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 11.2.2015.1705
FileDescription: 一键GHOST硬盘版卸载辅助程序
ProductName: 一键GHOST硬盘版
ProductVersion: 11.2.2015.1705
CompanyName: DOS之家
LegalCopyright: DOS之家 http://doshome.com 葛明阳
Comments: 1KEY GHOST HD v2015.07.05
Translation: 0x0804 0x04b0

Malware.AI.3219852382 also known as:

BkavW32.AIDetect.malware2
LionicVirus.Win32.Nimnul.lhYK
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.32532475
FireEyeGeneric.mg.b944f074b1944632
ALYacTrojan.GenericKD.32532475
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
K7AntiVirusAdware ( 004b897e1 )
K7GWAdware ( 004b897e1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/S-1a931a93!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.OnlineGames-1924
BitDefenderTrojan.GenericKD.32532475
NANO-AntivirusTrojan.Win32.Clicker.eajutv
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastFileRepMetagen [Malware]
Ad-AwareTrojan.GenericKD.32532475
SophosGeneric PUA FN (PUA)
DrWebTrojan.Click2.42995
ZillyaAdware.BrowseFox.Win32.138547
McAfee-GW-EditionBehavesLike.Win32.Trojan.ph
EmsisoftTrojan.GenericKD.32532475 (B)
GDataWin32.Riskware.FlyStudio.C
WebrootW32.Malware.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASCommon.FB
ViRobotBackdoor.Win32.Hupigon.50222
MicrosoftTrojan:Win32/Occamy.C37
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!B944F074B194
VBA32Trojan.KillFiles
MalwarebytesMalware.AI.3219852382
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/FlyStudio.C!tr
AVGFileRepMetagen [Malware]
Cybereasonmalicious.4b1944
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3219852382?

Malware.AI.3219852382 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment