Malware

How to remove “Malware.AI.3631848149”?

Malware Removal

The Malware.AI.3631848149 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3631848149 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3631848149?


File Info:

name: D2027B77C76967757D57.mlw
path: /opt/CAPEv2/storage/binaries/38f8b1b334ebc88c7a560ac52b9e4d00a08db81156af6148c828d13d66c58458
crc32: 346A464A
md5: d2027b77c76967757d57c93df8324568
sha1: 417881599a6bf60b1183a44dccc84a353b481e51
sha256: 38f8b1b334ebc88c7a560ac52b9e4d00a08db81156af6148c828d13d66c58458
sha512: 302a2f9bfb4eecc51d33c837e3a2ff7baa9e64e328a98a1e1fb1ec6342ae42f5e714f389f2740bf3050c803c791db77ba3da16055db822b151df508e17a2c2d0
ssdeep: 768:/F0O0fsrLYnBxLCan24CzSyKJgqEZeDmrmts1lyaHMRaeL:/FdWLy4Aig6GLUfL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14613AE84B58C9452CD650A308663BE78813FBEE8D8294B67A2C8FF4F25F7441783351B
sha3_384: f10633a12f0b26ec84f729d5ccce2a14044c7963142faf20d620d313e04ed1d63de396e46064b45ca27f555cb495b86c
ep_bytes: 60be00d040008dbe0040ffff5783cdff
timestamp: 2011-04-07 02:01:05

Version Info:

CompanyName: QQ:727652410
ProductName: 3D黑鹰
FileVersion: 1.00
ProductVersion: 1.00
InternalName: 3D黑鹰内部版本
OriginalFilename: 3D黑鹰内部版本.exe
Translation: 0x0804 0x04b0

Malware.AI.3631848149 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Tedy.455586
FireEyeGeneric.mg.d2027b77c7696775
SkyhighBehavesLike.Win32.Generic.ph
ALYacGen:Variant.Tedy.455586
MalwarebytesMalware.AI.3631848149
SangforTrojan.Win32.Agent.Vk8u
AlibabaTrojanDownloader:Win32/DownLdr.683cf1a2
Cybereasonmalicious.99a6bf
ArcabitTrojan.Tedy.D6F3A2
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Tedy.455586
EmsisoftGen:Variant.Tedy.455586 (B)
VIPREGen:Variant.Tedy.455586
Trapminemalicious.moderate.ml.score
SophosMal/DownLdr-O
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
Kingsoftmalware.kb.b.789
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Tedy.455586
GoogleDetected
McAfeeRDN/Generic.dx
VBA32BScope.Trojan.Danginex
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09KI23
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.3631848149?

Malware.AI.3631848149 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment