Malware

Malware.AI.3984924944 (file analysis)

Malware Removal

The Malware.AI.3984924944 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3984924944 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Malware.AI.3984924944?


File Info:

name: 61465D8DA228DD01D1E1.mlw
path: /opt/CAPEv2/storage/binaries/9fd244503adb0fcb15a66a384f0dac9a45761612974ab3cf5804f59fb1072643
crc32: A812A6DD
md5: 61465d8da228dd01d1e159a7cb6286c0
sha1: 5875d234b04efd44423212ba74832dcbf3e3b258
sha256: 9fd244503adb0fcb15a66a384f0dac9a45761612974ab3cf5804f59fb1072643
sha512: 526dd846321e13e01c3bc0892041d6e2da7777f89d182e9cd0fcd0bc79426f261a0955b16c7b32a13a9cd98929377afbcc5bba7034bac5611889587c775d264e
ssdeep: 768:K8vNuiiXIgHyPXtSo1dWnLmTiuLhSzSKq/A4Bxk40DhlbPGNvhgo:PNuiiXIgHyVdHI/yhjKGBa1tRORhgo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116D38C8A2E5C7B8BCBD4D930920EBABCCDA8FE19B9D4DD345698F2351211D72D60D603
sha3_384: 3baf1fa193bbfa8dc4548a6b6ffad6b3c95e0c39da111b8950d3c638c394402d9143c552da5a767e81eb2528be39b2c9
ep_bytes: 558bec6aff68183e870068ac46490064
timestamp: 2010-08-19 10:20:48

Version Info:

0: [No Data]

Malware.AI.3984924944 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.7137500
FireEyeGeneric.mg.61465d8da228dd01
CAT-QuickHealTrojanDropper.Agent.S134567
ALYacTrojan.Generic.7137500
CylanceUnsafe
VIPRETrojan.Generic.7137500
SangforSuspicious.Win32.Save.ins
K7AntiVirusPassword-Stealer ( 004d073f1 )
BitDefenderTrojan.Generic.7137500
K7GWPassword-Stealer ( 004d073f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.4B2CD5FA21
VirITTrojan.Win32.Generic.BEVW
CyrenW32/A-3968f8ce!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.OnLineGames.QBG
APEXMalicious
ClamAVWin.Trojan.Agent-375797
KasperskyTrojan-Dropper.Win32.Agent.ndwg
AlibabaTrojanPSW:Win32/OnLineGames.67944d02
NANO-AntivirusTrojan.Win32.DragonMess.rqflw
CynetMalicious (score: 100)
ViRobotTrojan.Win32.A.DragonMess.3473408
TencentMalware.Win32.Gencirc.10b67a8d
Ad-AwareTrojan.Generic.7137500
ComodoPacked.Win32.MPEC.Gen@2oey7k
DrWebTrojan.Siggen5.18743
ZillyaTrojan.DragonMess.Win32.256
TrendMicroTROJ_AGENT_036112.TOMB
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.7137500 (B)
IkarusTrojan-PWS.Win32.OnLineGames
JiangminTrojan/DragonMess.e
WebrootW32.Trojan.Dragonmess
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASCommon.3B
KingsoftWin32.Troj.DragonMess.e.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Generic.7137500
GoogleDetected
AhnLab-V3Trojan/Win32.DragonMess.R20072
McAfeeGenericRXAA-AA!61465D8DA228
MAXmalware (ai score=100)
VBA32Trojan.DragonMess
MalwarebytesMalware.AI.3984924944
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_AGENT_036112.TOMB
RisingStealer.OnLineGames!8.131 (TFE:4:oGZkLB9U1EH)
SentinelOneStatic AI – Malicious PE
FortinetW32/KRYPTIK.TH!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.da228d
AvastWin32:Evo-gen [Trj]

How to remove Malware.AI.3984924944?

Malware.AI.3984924944 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment