Malware

Malware.AI.3916988846 removal guide

Malware Removal

The Malware.AI.3916988846 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3916988846 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.3916988846?


File Info:

name: 46C307632759B9E275AD.mlw
path: /opt/CAPEv2/storage/binaries/1dc787329f03b4c026ed37aff6fdf385e224f955d0c4ee496cc08f1ed959fe89
crc32: 180FEFA8
md5: 46c307632759b9e275ad9161f52954e5
sha1: dd10a4a36fa2dee352cfd94c3d8918586590124d
sha256: 1dc787329f03b4c026ed37aff6fdf385e224f955d0c4ee496cc08f1ed959fe89
sha512: 254aba9206a7b16c1152b9bebfe47908a596ce3225a9c0728fc29be8a1f1c2900d2c99ce42299a4166421cb44624353d316ae18c548b7825cf2845bcc36a09d8
ssdeep: 98304:0IMA0cftJjI0YOumrPuvViJb3XOp+wZAqpWm1Siv8t9SP3POUOeUX1ObCbBiz/zL:mA0cGO2In6vYtoWaBIBWVMTFxDAH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E126334B3055D881E42D9D76EF92E67D02074C9ABE498C579930FF0C4EFC6C26AEA316
sha3_384: 78f78a733e1cd254c6c2eb228c3849bed3f757aa55b48bc9c30d0b040447e5506e3e0b4253c2c897cb7cccb35762d1d8
ep_bytes: 60be008075008dbe0090caff5783cdff
timestamp: 2020-08-09 15:26:09

Version Info:

FileVersion: 10.13.4.2
FileDescription: 青蛙盒子
ProductName: 灭霸青蛙盒子
ProductVersion: 10.13.4.2
CompanyName: sky
LegalCopyright: UI制作联系 QQ:1164557342
Comments: 青蛙盒子
Translation: 0x0804 0x04b0

Malware.AI.3916988846 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader44.23825
MicroWorld-eScanTrojan.GenericKD.36426074
FireEyeGeneric.mg.46c307632759b9e2
ALYacTrojan.GenericKD.36426074
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AlibabaBackdoor:Win32/Poison.df5d171d
Cybereasonmalicious.32759b
BitDefenderThetaGen:NN.ZexaF.34114.@pMfaemhMIkb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0GLQ21
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyHEUR:Backdoor.Win32.Poison.pef
BitDefenderTrojan.GenericKD.36426074
NANO-AntivirusTrojan.Win32.Blamon.hrxmzd
AvastWin32:MiscX-gen [PUP]
Ad-AwareTrojan.GenericKD.36426074
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
ZillyaTrojan.Blamon.Win32.1763
TrendMicroTROJ_GEN.R002C0GLQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.GenericKD.36426074 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.5LSHNI
JiangminTrojan.Blamon.amg
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1138808
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.FlyStudio.a
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D22BD15A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R354158
McAfeeGenericRXAA-AA!46C307632759
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.3916988846
APEXMalicious
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
YandexRiskware.BlackMoon!ixcQmXkfz7U
IkarusTrojan.Black
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:MiscX-gen [PUP]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.3916988846?

Malware.AI.3916988846 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment