Malware

Malware.AI.3862801660 removal guide

Malware Removal

The Malware.AI.3862801660 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3862801660 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.3862801660?


File Info:

crc32: 4A277A70
md5: 0fa253b38a1acbc1394d730812e66afb
name: 0FA253B38A1ACBC1394D730812E66AFB.mlw
sha1: 8fe409e80e1f125650a8d1ebdd498fe6d1cfe49b
sha256: 836d4302da1a6dc72116f5832b05882ad4050d33b8c55174c8f03565899bcf28
sha512: d66554209578fc7ec6424af9b77751a3fd5d5a4f3a2eed61e908768f238df7093f53f3a83a6ce82a5da31e75df510779fa98cbc0ea94be96c9a112defb1a713b
ssdeep: 24576:znpdNK+gIkrifC9jHeG8STbXn5VDZylPlFEX8PsMv03QXE4NSlOT/E:jfy3ECt+G8STz5XylPlFEX8PsMOOHSq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5cf0x4e91x8f6fx4ef6x8363x8a89x51fax54c1
FileVersion: 2.0.2.2
CompanyName: x5cf0x4e91x8f6fx4ef6
Comments: x5cf0x4e91x8f6fx4ef6x8363x8a89x51fax54c1
ProductName: x5cf0x4e91x8f6fx4ef6
ProductVersion: 2.0.2.2
FileDescription: x5cf0x4e91x8f6fx4ef6x8363x8a89x51fax54c1
Translation: 0x0804 0x04b0

Malware.AI.3862801660 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004571581 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.186586
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004571581 )
Cybereasonmalicious.38a1ac
BaiduWin32.Packed.VMProtect.a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Packed.Q potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.186586
MicroWorld-eScanGen:Variant.Ursu.186586
TencentWin32.Trojan.Generic.Jmg
Ad-AwareGen:Variant.Ursu.186586
SophosMal/VMProtBad-A
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34170.uL0@aGhpHaib
McAfee-GW-EditionBehavesLike.Win32.Autorun.tc
FireEyeGeneric.mg.0fa253b38a1acbc1
EmsisoftGen:Variant.Ursu.186586 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Black.Gen2
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tnega!ml
GDataGen:Variant.Ursu.186586
Acronissuspicious
McAfeeArtemis!0FA253B38A1A
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3862801660
TrendMicro-HouseCallTROJ_GEN.R005C0RIJ21
RisingTrojan.Generic@ML.100 (RDML:2/jjS1jUn9irRiHSF9sJCg)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyStudio_Packed
AVGWin32:Malware-gen

How to remove Malware.AI.3862801660?

Malware.AI.3862801660 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment