Malware

Should I remove “Malware.AI.3800365927”?

Malware Removal

The Malware.AI.3800365927 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3800365927 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3800365927?


File Info:

name: 8011B28CF4F6075E4A0D.mlw
path: /opt/CAPEv2/storage/binaries/5f21d9d5246e17b9241c6e006100524d86763e137b03edddb68fff9b20f4b6aa
crc32: 5FFE65CF
md5: 8011b28cf4f6075e4a0dd2b855c003bd
sha1: 57f858050131e9dabbc65621a98e1c8af2b9bb9e
sha256: 5f21d9d5246e17b9241c6e006100524d86763e137b03edddb68fff9b20f4b6aa
sha512: 027c7d491cf0456a7475eb2e44b48da5c06662e69fa636c1e68ddf5e1175f7b957e60a15be2fefdf0018a3611b43ed6ed40a078da2becaa95e3a3bbad17f07eb
ssdeep: 1536:vm+/T0ERhZeRmxykZ8jYZK0W+SfTBGgJnJYdSfFom+/T:vm+IED2mxPZ8EZK0WTBxmm+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1A34B23AE79512BC2648A714CF5E6FF7527ED2602019E13658AEF041E639037CA7E3D
sha3_384: 8c90b928d765cdb92d31e4674949510e0c63ddd1234ba7b1e5107d591b6415e1070b4ea5ad96cfa9499f2a75d2ba3906
ep_bytes: 68e05f4000e8eeffffff000000000000
timestamp: 2010-01-23 10:31:11

Version Info:

Translation: 0x0804 0x04b0
ProductName: wwwed2
FileVersion: 1.03.0004
ProductVersion: 1.03.0004
InternalName: 台湾十八美女
OriginalFilename: 台湾十八美女.exe

Malware.AI.3800365927 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.Heur.VP2.gm0@aqGTnsdb
SkyhighBehavesLike.Win32.BadFile.cm
McAfeeArtemis!8011B28CF4F6
Cylanceunsafe
VIPREGen:Trojan.Heur.VP2.gm0@aqGTnsdb
CrowdStrikewin/malicious_confidence_60% (W)
ArcabitTrojan.Heur.VP2.EC6810
APEXMalicious
BitDefenderGen:Trojan.Heur.VP2.gm0@aqGTnsdb
SUPERAntiSpywareTrojan.Agent/Gen-GalPic
EmsisoftGen:Trojan.Heur.VP2.gm0@aqGTnsdb (B)
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.851
GDataGen:Trojan.Heur.VP2.gm0@aqGTnsdb
BitDefenderThetaAI:Packer.FBB0E8D520
ALYacGen:Trojan.Heur.VP2.gm0@aqGTnsdb
VBA32BScope.Worm.Vabroran
MalwarebytesMalware.AI.3800365927
TrendMicro-HouseCallTROJ_GEN.R002H09L723
RisingTrojan.Win32.Generic.155DDED8 (C64:YzY0Oo0MLYRgUcm/)
MaxSecureTrojan.Malware.185274636.susgen
Cybereasonmalicious.50131e
DeepInstinctMALICIOUS

How to remove Malware.AI.3800365927?

Malware.AI.3800365927 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment