Malware

Malware.AI.3838214169 information

Malware Removal

The Malware.AI.3838214169 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3838214169 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3838214169?


File Info:

name: B68FF23D7A32304642E7.mlw
path: /opt/CAPEv2/storage/binaries/d1a90060ba3ee351bfe0b90d8211756c828c0845aaeadbc58b18d6e728ed9ef0
crc32: 70E3357D
md5: b68ff23d7a32304642e7c769110fd6f8
sha1: 7e7bcf928aace72c95d36aa174e064f752050c8f
sha256: d1a90060ba3ee351bfe0b90d8211756c828c0845aaeadbc58b18d6e728ed9ef0
sha512: 28ad0612d09cb05364a2072563af9e5dbcc74f2c98a1f5f6ddcc3308f021743cd6bbd470b29561df59567c315b1994ae891f6bde81bddccf7f8c5158f7f3d3cf
ssdeep: 12288:iO808FpVTrLDSc4C4k6yDP+TG8tDWcpqR:mhFTucFDPoG8Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DA402B3B96B42A4E1303B31ED5B89E6569CBC2C4BB00D4770D9FE0E753B5666E06E10
sha3_384: 352b845b80f6081f2afaf1f822ea0855835b86a2611883ac679e1a631e4e2844d6341109fde7f2ed5c4d83c734a0f4d4
ep_bytes: 60be00d04c008dbe0040f3ff57eb0b90
timestamp: 2018-07-29 06:42:53

Version Info:

FileVersion: 1.0.0.0
FileDescription: 支持千兆网络
ProductName: 局域网文件传送工具
ProductVersion: 1.0.0.0
CompanyName: 农民也懂高压电
LegalCopyright: 农民也懂高压电 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Malware.AI.3838214169 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lLmM
Elasticmalicious (moderate confidence)
FireEyeGeneric.mg.b68ff23d7a323046
CAT-QuickHealHacktool.Flystudio.16558
Cylanceunsafe
SangforTrojan.Win32.FlyStudio.Vx1w
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.28aace
CyrenW32/Trojan.CLL.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.PUPStudio.imfuci
McAfee-GW-EditionBehavesLike.Win32.Backdoor.gc
Trapminesuspicious.low.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusPUA.FlyStudio
GDataWin32.Trojan.PSE.1KQMTX4
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftPUA:Win32/Presenoker
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2673604
McAfeeArtemis!B68FF23D7A32
VBA32BScope.Backdoor.Poison
MalwarebytesMalware.AI.3838214169
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CE723
RisingTrojan.Generic@AI.100 (RDML:FFeGYAsclcQ7g91gvPxW5w)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/Generic_PUA_HO
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Malware.AI.3838214169?

Malware.AI.3838214169 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment