Malware

About “Malware.AI.3890472659” infection

Malware Removal

The Malware.AI.3890472659 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3890472659 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Icelandic
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3890472659?


File Info:

name: 855A4A6DC6BBBE50FF22.mlw
path: /opt/CAPEv2/storage/binaries/4ba62005fa74c9a9f791e5457933389a0fbc2bddb936c25a3daa82b3f9e82890
crc32: 3A47025A
md5: 855a4a6dc6bbbe50ff2239f3f5e1031b
sha1: ae69a69c9c1c4b36b44ea166af38bd589fc2c1ce
sha256: 4ba62005fa74c9a9f791e5457933389a0fbc2bddb936c25a3daa82b3f9e82890
sha512: 97d5433471ba006e3d3791423177d3f5a52b924a153a260aee607858c2d8c20d912e2bde2d74c4a4d58dfa82188d572304177248669a3194431f7d57697bfb15
ssdeep: 24576:u2Y7LyWgyRMPiqt9a8KdsqieEX6Atu9co5sq18UEAqGf:uRzgEMaqt9a8dqAXE9cYsq1X3
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T17A654B71869C14A5C1E790FDC2124546F4E2B8555791B2F322AC1F2F6E0FAC6C73EBA2
sha3_384: 2d02e972fdb5ff8268e3abf56308440efeb2b426aed737c6c793fb622dd203e54f51fa81e391c1643ca5ec84dd3500b8
ep_bytes: 4883ec28e8bf0500004883c428e976fe
timestamp: 2019-03-08 19:08:58

Version Info:

CompanyName: StateLab.
FileDescription: StateLab
FileVersion: 1.0.2.8
InternalName: statelab.exe
LegalCopyright: StateLab. 2019
OriginalFilename: statelab.exe
ProductName: StateLab
ProductVersion: 1.0.2.8
Translation: 0x040f 0x04b0

Malware.AI.3890472659 also known as:

LionicRiskware.Win64.CoinMiner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.BitCoinMiner.IdleBuddy.2
FireEyeGeneric.mg.855a4a6dc6bbbe50
ALYacGen:Variant.Application.BitCoinMiner.IdleBuddy.2
MalwarebytesMalware.AI.3890472659
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRiskWare:Win64/CoinMiner.0fa56fec
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Adware.OpenSUpdater.A
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:RiskTool.Win64.CoinMiner.gen
BitDefenderGen:Variant.Application.BitCoinMiner.IdleBuddy.2
TencentWin64.Adware.Opensupdater.Dzju
Ad-AwareGen:Variant.Application.BitCoinMiner.IdleBuddy.2
VIPREWin64.Adware.OpenSUpdater
SophosGeneric PUA KO (PUA)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.CoinMiner.nc
AviraHEUR/AGEN.1108436
MAXmalware (ai score=75)
GridinsoftRansom.Win64.Gen.sa
ArcabitTrojan.Application.BitCoinMiner.IdleBuddy.2
GDataGen:Variant.Application.BitCoinMiner.IdleBuddy.2
CynetMalicious (score: 100)
Acronissuspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CKS21
YandexTrojan.GenAsa!KbCqxXcXMHs
IkarusAdWare.Opensupdater
MaxSecureTrojan.Malware.74246856.susgen
FortinetAdware/OpenSUpdater
WebrootW32.Malware.Gen
Cybereasonmalicious.dc6bbb

How to remove Malware.AI.3890472659?

Malware.AI.3890472659 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment