Malware

Malware.AI.3850624388 removal

Malware Removal

The Malware.AI.3850624388 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3850624388 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3850624388?


File Info:

name: 16E627DBE730488B1C3D.mlw
path: /opt/CAPEv2/storage/binaries/63615ce2294ea65a061bdb51ab0771c12efcf4e77770f03a2826d57354f843ff
crc32: 4F648E0B
md5: 16e627dbe730488b1c3d448bfc9096e2
sha1: 5d47f273a2898724fc518e3dc9a13ba629b51c5a
sha256: 63615ce2294ea65a061bdb51ab0771c12efcf4e77770f03a2826d57354f843ff
sha512: 7dd909bca81383eda5aaa4afc49bc3d589c887db283175ef66c44029e7ddf07c0dad7b9a58a05c87978dcfd22f595100d992ec573ed7d9abf5ec058e3f698c71
ssdeep: 1536:qzSQHmEvoUjX4dRSEqSoiT8riDcHYGCHzmYcomT:SSQHmEdEEiY4dijT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB736A00A7099BC9E0A501312255AB7758B46C35B14FA07FF7C36DA678B8BD39268F4F
sha3_384: 850086b854f73ac01658f1adaefdfe7037181ed7727f6a02e5f71e315d2740243bf6cff0778bb6558fa56b1cace53ac3
ep_bytes: 558bec6aff6870b2001068249a001064
timestamp: 2014-08-25 01:22:20

Version Info:

CompanyName: Microsoft Corporation
FileDescription: IE Crash Detection
FileVersion: 7.00.5730.13 (longhorn(wmbla).070711-1130)
InternalName: iedw
LegalCopyright: © Microsoft Corporation. All rights reserved.
OleSelfRegister:
OriginalFilename: IEDW.EXE
ProductName: Windows® Internet Explorer
ProductVersion: 7.00.5730.13
Translation: 0x0409 0x04b0

Malware.AI.3850624388 also known as:

BkavW32.AIDetectMalware
CyrenCloudRisk/WIN_PE.63615ce2!Threatlookup
LionicTrojan.Win32.Ixeshe.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ser.Fragtor.3487
FireEyeGeneric.mg.16e627dbe730488b
SkyhighBehavesLike.Win32.Generic.lc
ALYacBackdoor.Agent.Threebyte
Cylanceunsafe
ZillyaTrojan.Agent.Win32.483100
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 00549aaf1 )
AlibabaTrojan:Win32/Ixeshe.6562f1d2
K7GWTrojan ( 00549aaf1 )
Cybereasonmalicious.3a2898
BitDefenderThetaAI:Packer.723C1FB91F
VirITTrojan.Win32.DownLoader11.BTXO
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Ixeshe.Q
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Threebyte-1
KasperskyTrojan.Win32.Agent.ahsgd
BitDefenderGen:Variant.Ser.Fragtor.3487
NANO-AntivirusTrojan.Win32.Agent.degbny
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.115dc4c0
Ad-AwareGen:Variant.Ser.Fragtor.3487
EmsisoftGen:Variant.Ser.Fragtor.3487 (B)
F-SecureHeuristic.HEUR/AGEN.1369786
DrWebTrojan.DownLoader11.31032
VIPREGen:Variant.Ser.Fragtor.3487
TrendMicroTROJ_GEN.R034E01KM14
Trapminemalicious.high.ml.score
SophosMal/PdfExDr-B
IkarusTrojan.Win32.Ixeshe
JiangminTrojan/Agent.inob
AviraHEUR/AGEN.1369786
Antiy-AVLTrojan[APT]/Win32.Apt12
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Malagent!MSR
XcitiumMalware@#3784530ofvkjt
ArcabitTrojan.Ser.Fragtor.DD9F
ViRobotBackdoor.Win32.Agent.75776.G
ZoneAlarmTrojan.Win32.Agent.ahsgd
GDataGen:Variant.Ser.Fragtor.3487
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C554494
McAfeeArtemis!16E627DBE730
MAXmalware (ai score=100)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesMalware.AI.3850624388
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R034E01KM14
RisingTrojan.Ixeshe!8.6AB (TFE:5:aCDSWCLKBHK)
YandexTrojan.Agent!M1giKNZA0z4
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.AHSGD!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3850624388?

Malware.AI.3850624388 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment