Malware

What is “Malware.AI.3857989384”?

Malware Removal

The Malware.AI.3857989384 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3857989384 virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.3857989384?


File Info:

name: 92D905D8BC667BF79356.mlw
path: /opt/CAPEv2/storage/binaries/a4d47a29dc1b1834cfd8177cf359258fd8125b55300d2837320c504bed83401d
crc32: 6EA0905F
md5: 92d905d8bc667bf79356914162c55220
sha1: 13b1fcdfac7ad9a4d2fc2862a95c7591a3ca574a
sha256: a4d47a29dc1b1834cfd8177cf359258fd8125b55300d2837320c504bed83401d
sha512: 09b2af236f220c858d1a49d8e6ed6614579bf5011fdb33623786e9e7113457c691fe76e9cb7b3d90d97546e2fd79cec8309c03a0a19c64f35f452088b035026d
ssdeep: 768:iQSCkwuciAfDmAJ2sDALphsh+Bp/yN8DnkaTut4:fRkdXcSAgsDS5je8Qby
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0C2D0667C58048BD4CA203B5310FB3F935E6A08229AC769F985E6DF3CC0D6D390E30A
sha3_384: cb8e8f9eefdd4a21cfc3e0d60bfe651054285780a4a9e1855ebce604e54ccb06f89d28c22b8955a733d5996a09f1365d
ep_bytes: 60b1012c90954d424090908350066e22
timestamp: 2010-01-08 11:35:55

Version Info:

0: [No Data]

Malware.AI.3857989384 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OnLineGames.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.508761
FireEyeGeneric.mg.92d905d8bc667bf7
SkyhighBehavesLike.Win32.ShodiWorm.mc
McAfeePWS-OnlineGames.ha
MalwarebytesMalware.AI.3857989384
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanPSW:Win32/OnLineGames.4734928f
K7GWTrojan ( 004bcce41 )
VirITTrojan.Win32.OLG.ZUA
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.OnLineGames.OQU
APEXMalicious
TrendMicro-HouseCallTSPY_ONLINEG.SMF
AvastWin32:Evo-gen [Trj]
ClamAVWin.Trojan.Onlinegames-13510
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Lazy.508761
NANO-AntivirusTrojan.Win32.OnLineGames.zqwee
RisingMalware.OnLineGames!8.E959 (TFE:4:0oeESLRSK8L)
EmsisoftGen:Variant.Lazy.508761 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.PWS.Wsgame.16109
ZillyaTrojan.OnLineGames.Win32.43180
TrendMicroTSPY_ONLINEG.SMF
Trapminemalicious.high.ml.score
SophosMal/HckPk-A
IkarusVirus.Win32.OnLineGames
JiangminTrojan/PSW.OnLineGames.bnkw
WebrootW32.InfoStealer.OnlineGames.Gen
GoogleDetected
AviraTR/Crypt.ULPM.Gen
VaristW32/OnlineGames.CW.gen!Eldorado
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
KingsoftWin32.Troj.Undef.a
MicrosoftPWS:Win32/OnLineGames
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Lazy.D7C359
ViRobotTrojan.Win.Z.Onlinegames.25972
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Lazy.508761
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnlineGameHack.R5352
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Lazy.508761
TACHYONTrojan-PWS/W32.WebGame.25972.C
Cylanceunsafe
PandaGeneric Malware
TencentWin32.Trojan-PSW.2.Gflw
YandexTrojan.GenAsa!6yPhg6YTIyM
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.2311059.susgen
BitDefenderThetaAI:Packer.F771C1CF1D
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudRiskWare:Win/OnLineGames.OQU

How to remove Malware.AI.3857989384?

Malware.AI.3857989384 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment