Malware

Malware.AI.3245141981 removal guide

Malware Removal

The Malware.AI.3245141981 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3245141981 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Malware.AI.3245141981?


File Info:

name: 0A4B2847C504795C2FF1.mlw
path: /opt/CAPEv2/storage/binaries/527c8e04d63956609b5a1ab28f462925004a9095007de56e4bced25870b7d91f
crc32: FD6332D5
md5: 0a4b2847c504795c2ff11bb7dff4a9eb
sha1: 0b754115cefe63b1fd770321f7588bc5af08affb
sha256: 527c8e04d63956609b5a1ab28f462925004a9095007de56e4bced25870b7d91f
sha512: 9e29780980c67a63f76208e4447a5bd270fae61469bef311ec0eba787b79badffe15e0b45d82d3a970227280d3fdebaee225f6e26c71c6c043378031238b4b05
ssdeep: 6144:e3Y3LNJNMQlrEOA7+TVlBbLjNnVAbP/gc8YPQk1rEWDt6doS4V41MfjhUy1bq6iU:eo3LNJNM5NKplIP/NdPQk1wIWoS4+cKC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C841212BDC2EA12C35D047D644A2ECC14292E2AE3AA16C735F4749FFC336E755263B5
sha3_384: f9b41a9e688a5db8609f4675f7c1e0c3188df8483d69e277e6348cb4f10025c90b25b7af7e829f5e6b0d41d13363d8e4
ep_bytes: 60be00b047008dbe0060f8ff5789e58d
timestamp: 2010-01-26 12:29:39

Version Info:

FileDescription: 启动 Internet Explorer 浏览器
FileVersion: 5.1.2600.5512
LegalCopyright: 网上冲浪
LegalTrademarks: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 5.1.2600.5512
CompanyName: Internet Explorer 浏览器
Translation: 0x0804 0x04b0

Malware.AI.3245141981 also known as:

LionicTrojan.Win32.AutoIt.8!c
tehtrisGeneric.Malware
DrWebTrojan.DownLoader6.10204
MicroWorld-eScanTrojan.AutoIt.AJP
FireEyeGeneric.mg.0a4b2847c504795c
ALYacTrojan.AutoIt.AJP
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.1575
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.7c5047
VirITTrojan.Win32.Generic.IFZ
CyrenW32/Risk.LBXT-1949
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanClicker.Autoit.NCA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Autoit-6974227-0
KasperskyTrojan-Clicker.Win32.AutoIt.r
BitDefenderTrojan.AutoIt.AJP
NANO-AntivirusTrojan.Win32.AutoIt.wvyhg
AvastWin32:AutoIt-HE [Trj]
TencentWin32.Trojan.Autoit.Swhl
Ad-AwareTrojan.AutoIt.AJP
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanClicker.AutoIt.kji@2nruzb
BaiduWin32.Trojan-Clicker.Autoit.d
VIPRETrojan.AutoIt.AJP
McAfee-GW-EditionBehavesLike.Win32.Spyware.fc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.AutoIt.AJP (B)
JiangminTrojanClicker.AutoIt.kp
WebrootW32.Trojan.Comame
GoogleDetected
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan/Generic.ASCommon.11C
MicrosoftPWS:Win32/Zbot!ml
ViRobotTrojan.Win32.A.Clicker.390781
GDataTrojan.AutoIt.AJP
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.FakeMS.R45947
McAfeeArtemis!0A4B2847C504
MAXmalware (ai score=80)
VBA32TrojanClicker.AutoIt
MalwarebytesMalware.AI.3245141981
RisingTrojan.Win32.Autoit.erf (CLASSIC)
YandexTrojan.CL.Autoit.Gen
IkarusTrojan-Clicker.Win32.AutoIt
FortinetW32/StartPage.NQI!tr
AVGWin32:AutoIt-HE [Trj]
PandaTrj/Autoit.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3245141981?

Malware.AI.3245141981 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment