Malware

How to remove “Malware.AI.3883641602”?

Malware Removal

The Malware.AI.3883641602 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3883641602 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3883641602?


File Info:

name: 493DD6AF169CA01E5756.mlw
path: /opt/CAPEv2/storage/binaries/9f3b301db03b6567c91e90486e16599988abd306ce301bfe4de1bf0e925d85c0
crc32: D5143E58
md5: 493dd6af169ca01e575635a10234dca0
sha1: e54c5630c11d7759547b0fd00c2dd89f8a2338cf
sha256: 9f3b301db03b6567c91e90486e16599988abd306ce301bfe4de1bf0e925d85c0
sha512: f0024dcf05e790786acf9365fe830748a2122096a4a057fcf8350ded5d48a79bb909a7ea2c1db0528d6fba810517ef91c27750bbad09d17899082d2e511ad078
ssdeep: 24576:IAOcZwXYRe9OqZmgxYQ1jzEw4xJ64FnEXM3t22SeUfT2F1uFfijPMtt:mX9/mgxjCwmOABUbm1uFOs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17E451202B5D18571D4732A321A396B21AE3D7D206F35DE2F63E8292CCE351D17639BA3
sha3_384: 97998df53643d10d0e482fa4e9085f4b8e1730dc59799f1f2e94b78c1a3e8b98f79f95d838aeb39d792cedc3ea72d915
ep_bytes: e89a040000e98efeffff3b0d68d64300
timestamp: 2020-03-26 10:02:47

Version Info:

0: [No Data]

Malware.AI.3883641602 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
ALYacTrojan.GenericKD.38248563
CylanceUnsafe
SangforTrojan.Win32.Agent.xaliki
K7AntiVirusTrojan ( 0058bab91 )
AlibabaTrojan:Win32/BunituCrypt.7dda85ae
K7GWTrojan ( 0058bab91 )
Cybereasonmalicious.0c11d7
CyrenW32/S-536dd2d1!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EQSX
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.xaliki
BitDefenderTrojan.GenericKD.38248563
MicroWorld-eScanTrojan.GenericKD.38248563
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan.Agent.Pcjd
Ad-AwareTrojan.GenericKD.38248563
SophosMal/Generic-S
DrWebTrojan.Inject4.22929
TrendMicroTrojanSpy.Win32.NOON.UHBAZCLQZ
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.493dd6af169ca01e
EmsisoftTrojan.GenericKD.38248563 (B)
SentinelOneStatic AI – Suspicious SFX
GDataWin32.Trojan.BSE.19N9HYR
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.8B4163
GridinsoftTrojan.Win32.Downloader.sa
ArcabitTrojan.Generic.D247A073
MicrosoftTrojan:Win32/BunituCrypt.RTH!MTB
McAfeeArtemis!493DD6AF169C
VBA32Trojan.Agent
MalwarebytesMalware.AI.3883641602
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTrojanSpy.Win32.NOON.UHBAZCLQZ
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
YandexTrojan.Injector!Ztuv9vbR6cU
IkarusTrojan.Win32.Injector
FortinetW32/GenKryptik.FMFK!tr
AVGWin32:InjectorX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Malware.AI.3883641602?

Malware.AI.3883641602 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment