Malware

Malware.AI.3989526112 (file analysis)

Malware Removal

The Malware.AI.3989526112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3989526112 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3989526112?


File Info:

name: A97215BFFAA4B0DCD0C7.mlw
path: /opt/CAPEv2/storage/binaries/114c25bf2760f18e297207f0788a133c510674bbb7a0187bf9fc3d511357c612
crc32: C83EE5CA
md5: a97215bffaa4b0dcd0c7651482098301
sha1: 02e24c9ed375bf872d8090abf2d94acf8383cba3
sha256: 114c25bf2760f18e297207f0788a133c510674bbb7a0187bf9fc3d511357c612
sha512: b941f6594bdc3eb0f859cc7877248935fee8962396c74e0f7305309b1c05a330217a2f216308fe4ab14b9b1106e8515b87268301b237c2d5d35339425d51ad3c
ssdeep: 24576:cg9GK2af03OILk8uurKfsXINpEnsJ/OUeg8RLxoNSbEcVLV63xpH:cOmtkSJfnQGU3okgVV6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A857E22B2D19437C1732A7C9D1B939D983ABE102D3CA88A7BF51E4C4F396517D292D3
sha3_384: a14cbdcc73764ab32f17a82e630c57607014d7b981565595b97a70134914a478d90ca510d548964155b8dc68b26bf92c
ep_bytes: 558bec83c4f053b8c0394e00e8172bf2
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: 神马数据出品 www.gm73.com
FileDescription: Vip登陆器购买 QQ438098880
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Malware.AI.3989526112 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.69246214
FireEyeTrojan.GenericKD.69246214
SkyhighBehavesLike.Win32.ObfuscatedPoly.th
ALYacTrojan.GenericKD.69246214
Cylanceunsafe
VIPRETrojan.GenericKD.69246214
SangforTrojan.Win32.Agent.V8m0
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderTrojan.GenericKD.69246214
K7GWTrojan ( 7000000f1 )
APEXMalicious
RisingTrojan.Generic@AI.100 (RDML:76VGu2gKtENTZVuURASBow)
SophosGeneric Reputation PUA (PUA)
EmsisoftTrojan.GenericKD.69246214 (B)
IkarusTrojan.Agent
GDataTrojan.GenericKD.69246214
VaristW32/ABRisk.SENN-1292
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Siscos
Kingsoftmalware.kb.a.852
ArcabitTrojan.Generic.D4209D06
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Siscos.C5496689
McAfeeArtemis!A97215BFFAA4
DeepInstinctMALICIOUS
MalwarebytesMalware.AI.3989526112
TrendMicro-HouseCallTROJ_GEN.R002H09IB23
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.3989526112?

Malware.AI.3989526112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment