Malware

Malware.AI.3916332458 malicious file

Malware Removal

The Malware.AI.3916332458 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3916332458 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3916332458?


File Info:

name: 6027A8A7EB1AF5EE3595.mlw
path: /opt/CAPEv2/storage/binaries/75690b4ff4614753b03576924aa46f1dcfaecae2802db7590f290a73829fd083
crc32: 386B4301
md5: 6027a8a7eb1af5ee359567d432229968
sha1: e272bc908140469160349e6e23121fb42964caec
sha256: 75690b4ff4614753b03576924aa46f1dcfaecae2802db7590f290a73829fd083
sha512: 47f09d9f8648e07912205da8efa0b05d8b659a50d0bbc1a228878a34cf8e0093df17194c71053a5cbfe7e7cac5a03b0e3ac75b17e684e906b43d0fd59fbb74de
ssdeep: 6144:X9w2r06MAlw8XQ7toy+qR4jeoKIGnkjNLTNmvcKIPU:X9QL8XQRoCRgu7kNTNmvLr
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1876423D832A95F22E40D8630B52B85FA0366FE0B0B510F9A8635F2FD7934AD7471D51E
sha3_384: 021913f040588b528efccc6132f2443bab2be2d7bf730298998c116d3b6adf8d04ebc047a0d1c41c32ba2056991a539b
ep_bytes: 807c2408010f85e201000060be00c009
timestamp: 2021-08-07 11:06:44

Version Info:

FileVersion: 1.0.0.0
FileDescription: 内存画板
ProductName: 内存画板
ProductVersion: 1.0.0.0
CompanyName: 辛汉鹏
LegalCopyright: 辛汉鹏 版权所有
Comments: QQ:354033079 QQ群:772191729
Translation: 0x0804 0x04b0

Malware.AI.3916332458 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
SkyhighBehavesLike.Win32.Generic.fc
McAfeeRDN/Generic.com
MalwarebytesMalware.AI.3916332458
SangforTrojan.Win32.Agent.V2mc
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanPSW:Win32/OnlineGames.8fe00b91
BitDefenderThetaGen:NN.ZedlaF.36680.umSfaKMy9wjb
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Malware-gen
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Agent
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ViRobotAdware.Agent.336384.D
GDataWin32.Trojan.PSE.D733LJ
VaristW32/S-b9f587c1!Eldorado
AhnLab-V3Malware/Win.Generic.R442571
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06L823
RisingTrojan.Generic@AI.100 (RDML:y410c5VzryhAa/h/UqsWMw)
YandexTrojan.GenAsa!MUZbVW+A0S4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/PackedFlyStudio
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.3916332458?

Malware.AI.3916332458 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment