Malware

Malware.AI.1291766881 removal

Malware Removal

The Malware.AI.1291766881 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1291766881 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Steals private information from local Internet browsers

How to determine Malware.AI.1291766881?


File Info:

name: 75DEAB73E7EEBFC93593.mlw
path: /opt/CAPEv2/storage/binaries/7fa7330b778ce75f000f6615fadd68929a84a4239d1db11ce7e9db5a94819cf7
crc32: B4F20D84
md5: 75deab73e7eebfc935932ded17b4687e
sha1: 9b3f4d6e7c87b0ac457796e31291fd481251374d
sha256: 7fa7330b778ce75f000f6615fadd68929a84a4239d1db11ce7e9db5a94819cf7
sha512: e3c5fdff2eb6068e4c65514dfa7f71870782ff5d6b3d3e3f94fcd09a3198966ed3c38a189d4b1917894b3fa73364e224162dbd14385f2191843f8c07b70f9542
ssdeep: 24576:yhCybJqPxQfqXc989QpuD2Y9zjrd4FeLqgRM+cG0ecTkp1+Wx:ClqPHM9IQpux1e+cG0ecTkX+Wx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D65AF217643C071E5A101B029B9AF7ACD6CBD38577085CBB3D42E7999316D22A33F6E
sha3_384: 8af4a2d9f54ebb038968ec169538eb0557fb8fbd6d06f6bdba755a4971d2d84f9a191d75011fd6b9d368a12dc9553993
ep_bytes: e8510b0000e97afeffff558becff7510
timestamp: 2021-09-01 02:08:41

Version Info:

0: [No Data]

Malware.AI.1291766881 also known as:

LionicTrojan.Win32.Disco.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.976767
FireEyeGeneric.mg.75deab73e7eebfc9
ALYacGen:Variant.Razy.976767
MalwarebytesMalware.AI.1291766881
ZillyaTrojan.Disco.Win32.2625
SangforTrojan.Win32.Disco.gen
K7AntiVirusUnwanted-Program ( 00568e2f1 )
K7GWUnwanted-Program ( 00568e2f1 )
Cybereasonmalicious.e7c87b
BitDefenderThetaGen:NN.ZexaF.34182.AvW@aaceg!ci
CyrenW32/Trojan.RLSI-4289
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WJN21
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Disco.gen
BitDefenderGen:Variant.Razy.976767
AvastWin32:AdwareX-gen [Adw]
SophosGeneric PUA JL (PUA)
TrendMicroTROJ_GEN.R002C0WJN21
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SentinelOneStatic AI – Suspicious PE
EmsisoftGen:Variant.Razy.976767 (B)
APEXMalicious
AviraTR/Redcap.nkaab
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Razy.976767
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Woreflint.C4790543
McAfeeArtemis!75DEAB73E7EE
MAXmalware (ai score=87)
VBA32BScope.Adware.Presenoker
CylanceUnsafe
RisingMalware.Strealer!8.1EF (TFE:5:jiNkBhLYeLE)
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Disco
AVGWin32:AdwareX-gen [Adw]

How to remove Malware.AI.1291766881?

Malware.AI.1291766881 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment