Malware

Malware.AI.3548133386 removal tips

Malware Removal

The Malware.AI.3548133386 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3548133386 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3548133386?


File Info:

name: 21BC82F3D9AA7B2C7E73.mlw
path: /opt/CAPEv2/storage/binaries/f253eeed9e0d08525576a6c40e04c85eb2cd04914d66387ad36ea5e7e1aaf5e1
crc32: 4BF0FF9A
md5: 21bc82f3d9aa7b2c7e732defabb8333d
sha1: 828c3c8fca14c49f7256f701dd20aff866cd9a53
sha256: f253eeed9e0d08525576a6c40e04c85eb2cd04914d66387ad36ea5e7e1aaf5e1
sha512: 72f10b99812e1daeb786280c1c09750dcaa3a7bf000814825fd91c25da26a4e0abd1bd0ff0fdb68b38332d8b985aa012231919a8bcf6da6a066dcd4dca8ddf0c
ssdeep: 6144:vHRuWxnNR7/lWrUkII/NeFZQGrf53evkcGzibvfof/L4CzT+JfXXqjkMb/Yj8iMf:vHQ2NRJIf/NWJrffcfDgf/4NljRy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3948D47F901C6E3C50E0271581792929FB06C253D0AF64BB398F7BE2D357C16A9276B
sha3_384: 0358199ce651b7b634de6084c55bb362f0078c39dbdc279efceb9a7c144ea711d2391665ccc565df945a0eb33955ee12
ep_bytes: 6814164000e8f0ffffff000000000000
timestamp: 2004-11-04 12:18:18

Version Info:

Translation: 0x0804 0x04b0
Comments: 灭火器计算软件V1.0
CompanyName: 江西华杰建筑设计
FileDescription: 灭火器计算软件V1.0
LegalCopyright: 版权所有(C) 残域软件序列
LegalTrademarks: GPSJS
ProductName: 灭火器计算软件
FileVersion: 1.00
ProductVersion: 1.00
InternalName: mhqjs
OriginalFilename: mhqjs.exe

Malware.AI.3548133386 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.69954432
FireEyeGeneric.mg.21bc82f3d9aa7b2c
SkyhighBehavesLike.Win32.Sality.gh
McAfeeGenericRXAA-AA!21BC82F3D9AA
MalwarebytesMalware.AI.3548133386
SangforTrojan.Win32.Agent.Vij1
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.fca14c
ArcabitTrojan.Generic.D42B6B80
CynetMalicious (score: 100)
APEXMalicious
BitDefenderTrojan.GenericKD.69954432
NANO-AntivirusTrojan.Win32.Crypt.fbjeng
EmsisoftTrojan.GenericKD.69954432 (B)
VIPRETrojan.GenericKD.69954432
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
VaristW32/ABRisk.EMGK-7024
MAXmalware (ai score=85)
Kingsoftmalware.kb.a.998
GDataTrojan.GenericKD.69954432
GoogleDetected
ALYacTrojan.GenericKD.69954432
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09JR23
MaxSecureTrojan.Malware.219886473.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3548133386?

Malware.AI.3548133386 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment