Malware

Malware.AI.3794945829 removal tips

Malware Removal

The Malware.AI.3794945829 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3794945829 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Malware.AI.3794945829?


File Info:

name: 8D31DF80DCC0E9ED88F9.mlw
path: /opt/CAPEv2/storage/binaries/294398a493bd1a95e21ff495bea34c977f4e84be6594d869dbd5e705ca5d5989
crc32: EFC80EE5
md5: 8d31df80dcc0e9ed88f9c2f0b17f1e2f
sha1: 576d1b1da68d6e598e977fb0f139243e669a6a04
sha256: 294398a493bd1a95e21ff495bea34c977f4e84be6594d869dbd5e705ca5d5989
sha512: d55b0f35c59acec822122db70bd7224ca201079df52c1926615d5d2141257b8dd9b3734310c582207a2219981e8ed1bbcdb7ba003ac4c6c9c9328832625a9f04
ssdeep: 24576:m9o254RPXxQpV0bkDHctrBTyn7T/2zoWYyJ2OPTN+xRPO5NUgrBBalizj0WX:moRQ+rBW+cWpJKRmbUYzj0g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152752371BEA50435E9661BB0A17CBE143DB6FFF84D6884EE67B03E8D7531A408978213
sha3_384: 645f78841827acc8bbff98ebd7c588c22f7cd40e100445786ffaf18a71b92c2fe829fdbc0971afea81e770694d05c3b8
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:19:43

Version Info:

FileDescription: 西瓜影音安装程序
FileVersion: 1.1.2.1
LegalCopyright: Copyright 2010-2014 西瓜影音
ProductName: 西瓜影音安装程序
ProductVersion: 1.1.2.1
Translation: 0x0000 0x04b0

Malware.AI.3794945829 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.StartPage.2!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Dropper.tc
ALYacGen:Variant.Bulz.410346
Cylanceunsafe
VIPREGen:Variant.Bulz.410346
SangforPUP.NSIS.StartPage.Vjm6
K7AntiVirusTrojan ( 004f5e001 )
BitDefenderGen:Variant.Bulz.410346
K7GWTrojan ( 004f5e001 )
VirITPUP.Win32.Xinfu.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.NSIS.Agent.gq
NANO-AntivirusRiskware.Win32.StartPage.fboroq
MicroWorld-eScanGen:Variant.Bulz.410346
AvastWin32:Adware-gen [Adw]
RisingTrojan.StartPage/NSIS!1.C3A5 (CLASSIC)
EmsisoftGen:Variant.Bulz.410346 (B)
BaiduNSIS.Trojan.StartPage.h
F-SecureAdware.ADWARE/Agent.1576624
DrWebTrojan.DownLoader26.37171
ZillyaAdware.Agent.Win32.68430
TrendMicroTROJ_GEN.R002C0PBJ24
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.8d31df80dcc0e9ed
SophosMal/Generic-S
GDataGen:Variant.Bulz.410346
GoogleDetected
AviraADWARE/Agent.1576624
Antiy-AVLTrojan/Win32.AdLoad.bh
ArcabitTrojan.Bulz.D642EA
ViRobotAdware.Agent.1576624
ZoneAlarmnot-a-virus:AdWare.NSIS.Agent.gq
MicrosoftTrojan:Win32/Startpage!rfn
McAfeeGenericR-FIL!8D31DF80DCC0
MAXmalware (ai score=99)
VBA32AdWare.Agent
MalwarebytesMalware.AI.3794945829
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PBJ24
TencentNsis.AdWare.Agent.Ltgl
YandexPUA.Agent!W4pQgGZWVT8
IkarusTrojan.NSIS.StartPage
MaxSecureTrojan.Malware.121218.susgen
FortinetNSIS/StartPage.CL!tr
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
alibabacloudAdWare:Win/Bulz

How to remove Malware.AI.3794945829?

Malware.AI.3794945829 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment