Malware

Malware.AI.3661604243 removal tips

Malware Removal

The Malware.AI.3661604243 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3661604243 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3661604243?


File Info:

name: 10853DF8C54B3CC75732.mlw
path: /opt/CAPEv2/storage/binaries/68c1b296673bc58a6aec94de060aa757590a81aba9aabf976cbcacc448d1fb2b
crc32: 21A59AC9
md5: 10853df8c54b3cc7573239ec255071f9
sha1: 4eff79b10f77cd6d3c6c2fa4be183ef10f082a40
sha256: 68c1b296673bc58a6aec94de060aa757590a81aba9aabf976cbcacc448d1fb2b
sha512: abf4d6517268102d58da70d37bb1ddbfa2c26709c32bb0fafabf6ef3b273a57ba18a5d32688f4dac5bbaf7216437fd51cd7b78e9f61d88ab756b1fa1403acf39
ssdeep: 6144:0FlvC60dLy0+/FsuSGZW+tMKnF48rLRauSTvazEf9Y24jZbZ:0FlvC60xyR/FMUW+yu4MLUdTTC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8846C02FB649275C5E318748A53AB2525AAAEC13F30A6CF33883E4D1A395C57375F4B
sha3_384: a8f1b504d1de940768c67655eb009b3bf08e7c4b55217b191cd9f7914f8635f9ff7ea5b86f6b93ee69405086b81f7156
ep_bytes: 6a6068e0954400e83a120000bf940000
timestamp: 2010-09-16 21:13:22

Version Info:

FileVersion: 1.0.0.30
ProductVersion: 1.0.0.30
Translation: 0x0804 0x03a8

Malware.AI.3661604243 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Wsgame.28681
MicroWorld-eScanGen:Variant.OnlineGames.5
FireEyeGeneric.mg.10853df8c54b3cc7
CAT-QuickHealTrojan.OnLineGames.xi5
ALYacGen:Variant.OnlineGames.5
CylanceUnsafe
ZillyaTrojan.OnLineGames.Win32.76494
K7AntiVirusTrojan ( 0055e3dd1 )
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.8c54b3
BitDefenderThetaGen:NN.ZexaF.34294.xu2@aSPaOEeb
CyrenW32/FakeGame.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.RXZ
TrendMicro-HouseCallTROJ_STARTP.SML2
ClamAVWin.Trojan.OnlineGames-65
KasperskyTrojan-Downloader.Win32.Gamup.pxb
BitDefenderGen:Variant.OnlineGames.5
NANO-AntivirusTrojan.Win32.OnLineGames.cagpw
AvastWin32:BHO-ACI [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.OnlineGames.5
SophosML/PE-A + Troj/Darbyen-A
ComodoTrojWare.Win32.BHO.EFKMNB@4ok0yf
BaiduWin32.Trojan.BHO.n
VIPRETrojan.Win32.Darbyen.A (v) (not malicious)
TrendMicroTROJ_STARTP.SML2
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.OnlineGames.5 (B)
IkarusTrojan.Win32.StartPage
GDataGen:Variant.OnlineGames.5
JiangminTrojan/PSW.OnLineGames.ccgw
MaxSecureDownloader.Gamup.qmq
AviraTR/BHO.efkmnb
Antiy-AVLTrojan/Generic.ASMalwS.2A4B
KingsoftHeur.SSC.43597.1216.(kcloud)
ViRobotTrojan.Win32.PSWIGames.381240
MicrosoftTrojan:Win32/BHO.EF
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Onlinegamehack21.Gen
Acronissuspicious
McAfeeStartPage-NH
VBA32TrojanPSW.OnLineGames.xg
MalwarebytesMalware.AI.3661604243
APEXMalicious
RisingBackdoor.Agent!1.69D8 (CLASSIC)
YandexTrojan.GenAsa!6Ju1+ezyYvI
MAXmalware (ai score=86)
FortinetW32/ZLob.AAAA!tr.dldr
WebrootW32.Malware.Gen
AVGWin32:BHO-ACI [Trj]
PandaTrj/Lineage.LOE
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3661604243?

Malware.AI.3661604243 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment