Malware

Should I remove “Malware.AI.3824889944”?

Malware Removal

The Malware.AI.3824889944 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3824889944 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.3824889944?


File Info:

name: DE4BB120A68CDE3D707A.mlw
path: /opt/CAPEv2/storage/binaries/d6bdb66e53798b2b7f502f7c60c2c76a71562b04a1f86c09b7da817d31b17328
crc32: 1B7772DE
md5: de4bb120a68cde3d707aa09047dbbb96
sha1: d3815de72c9195cdff58395b81637af7880d9b88
sha256: d6bdb66e53798b2b7f502f7c60c2c76a71562b04a1f86c09b7da817d31b17328
sha512: 0876281978f6b510f740ab57a17dcda8d8bd1b475d26280a58a951094ad3797405cd6e292966b363885bf9d76c697cae6ff0512966c8eb89847ce93c425d3013
ssdeep: 6144:XRRmUUqTH+MxkhJny6Ay0577+Yx2tTKsNPjK5EwvPo7Si/lHe8fOdGZb:XizqTH+Rhd3ypC62NN7KxXoLl+kOd0b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14674127DE336841BC17C6A3C6493CAB557155C12DA4A870F6F78FF4D38B07A07A122A9
sha3_384: 2c23a7c1db937cec051d82c7e768205e8de6f517f51956eddd7b949ce25f73b5bbfdbb5d4999c2b1e12396a0bad81280
ep_bytes: 60be00e049008dbe0030f6ff5783cdff
timestamp: 2015-04-25 16:07:19

Version Info:

FileVersion: 1.0.3.0
FileDescription: 计划管理 Beta1.0.4
ProductName: 计划管理
ProductVersion: 1.0.3.0
CompanyName: Diamonds
LegalCopyright: Diamonds版权所有,联系QQ:820957570
Comments: 计划管理 公开测试版1.0.4
Translation: 0x0804 0x04b0

Malware.AI.3824889944 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.lyZ2
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.de4bb120a68cde3d
SkyhighBehavesLike.Win32.Generic.fc
McAfeeArtemis!DE4BB120A68C
Cylanceunsafe
SangforTrojan.Win32.Agent.V4lq
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.36802.vmKfaqYqs6bb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H0CL723
AvastWin32:Malware-gen
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32
GoogleDetected
VaristW32/OnlineGames.HG.gen!Eldorado
Antiy-AVLRiskWare/Win32.FlyStudio.a
MicrosoftPUA:Win32/Presenoker
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
GDataWin32.Application.PSE.1OV7PVV
CynetMalicious (score: 100)
MalwarebytesMalware.AI.3824889944
RisingTrojan.Tiggre!8.ED98 (CLOUD)
YandexTrojan.GenAsa!84aUJ/mh73E
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyApplication
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (W)

How to remove Malware.AI.3824889944?

Malware.AI.3824889944 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment