Malware

What is “Malware.AI.3508312249”?

Malware Removal

The Malware.AI.3508312249 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3508312249 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3508312249?


File Info:

name: 8D9C981369E0B6C44076.mlw
path: /opt/CAPEv2/storage/binaries/946f0485fd828f609356542cf6b97a9d342faefa112313f7c697dd8a8d6f99aa
crc32: 6BCB638B
md5: 8d9c981369e0b6c44076b63c77567224
sha1: ac024dd4e25f1bed5ace3a1cc759473cc74dea0c
sha256: 946f0485fd828f609356542cf6b97a9d342faefa112313f7c697dd8a8d6f99aa
sha512: 8b1117781932c0272c8a50bd6866de2b8efaa84b9c51f9db8c3acf747cb01b66c872304037506b6120031dfc06de8605166fd1acea1f267a4eb11484692b866e
ssdeep: 24576:JPuLcpjjid2omNEgdorXK/Ye1SVw1WoAaWmQP2pKze24iyt5Ga/P:dpXWK/YVwO2pueViQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB759E31F7819833D1231E384C1B9698A939BF516E28A85B7BED1E4C1FB9A513C243D7
sha3_384: 26f6caf66582d731a0c5d267cdbd087ddef17cd763ed5d7da101cb13fa50917f3bc7d82961e91547df5c8d23e5672457
ep_bytes: 558bec83c4f053b8c4995100e803b8ee
timestamp: 2021-11-20 03:34:25

Version Info:

CompanyName: 凤凰工作室
FileDescription: 凤凰传世反外挂登录器
FileVersion: 1.1.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: 凤凰登陆器
ProductVersion: Phoenixer
Comments: 凤凰工作室荣誉出品
Translation: 0x0804 0x03a8

Malware.AI.3508312249 also known as:

LionicTrojan.Win32.OnLineGames.d!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.369408
FireEyeGen:Variant.Zusy.369408
McAfeeArtemis!8D9C981369E0
MalwarebytesMalware.AI.3508312249
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/OnLineGames.ea984dad
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.369e0b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Woool.H
APEXMalicious
KasperskyHEUR:Trojan-GameThief.Win32.OnLineGames.gen
BitDefenderGen:Variant.Zusy.369408
AvastWin32:Trojan-gen
TencentWin32.Trojan-gamethief.Onlinegames.Edya
Ad-AwareGen:Variant.Zusy.369408
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WKP21
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
EmsisoftGen:Variant.Zusy.369408 (B)
JiangminTrojan.PSW.OnLineGames.bsa
AviraHEUR/AGEN.1133921
MAXmalware (ai score=84)
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Zusy.D5A300
ViRobotTrojan.Win32.Z.Zusy.1692160
GDataGen:Variant.Zusy.369408
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.369408
VBA32TScope.Trojan.Delf
TrendMicro-HouseCallTROJ_GEN.R002C0WKP21
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Woool.C!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Malware.AI.3508312249?

Malware.AI.3508312249 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment