Malware

How to remove “Malware.AI.1376887679”?

Malware Removal

The Malware.AI.1376887679 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1376887679 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.1376887679?


File Info:

name: 61EFCF81F3F4F09BBE04.mlw
path: /opt/CAPEv2/storage/binaries/ad65b9d67182eab7243a19460b821c9981840f1151387b7c3adc6c38104422e0
crc32: 61F316AA
md5: 61efcf81f3f4f09bbe049e59b53fe7ab
sha1: e348f865f9203050059b7eb2f0fe16575db987b1
sha256: ad65b9d67182eab7243a19460b821c9981840f1151387b7c3adc6c38104422e0
sha512: fdec8446367b8163c70a1a8572d5dea257077d726f6dddce5fc2121b2c73495f6aae7f656e146481763b417fe1366b42306ed8b2708c30daaa906db30a361578
ssdeep: 24576:M3er5WEHr4ZLmvIdOBYf7km+9VqkVFWSC7cSMHdtK6YoQx2j9aN4a3:R5Wc4l9dO2kphFWSCISitxYLgZ4F3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC75F0D79000AB92F14E0A7275A5ACDF305E3ED6D8D4723C2850F67919F64C6E72AE0B
sha3_384: 16e5ee845946c335cd348bac945d0f2820de9b64e16c27466c56f1d167f12d013bb8aaea82e1b65b96bc497984c2838a
ep_bytes: 60be00b055008dbe0060eaff5783cdff
timestamp: 2021-02-14 06:59:57

Version Info:

FileVersion: 3.3.5.0
FileDescription: 樱花网络科技公司
ProductName: 300herobox
ProductVersion: 3.3.5.0
CompanyName: 红尘一世
LegalCopyright: 樱花网科版权所有
Comments: 樱花网络科技公司
Translation: 0x0804 0x04b0

Malware.AI.1376887679 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Graftor.792178
FireEyeGeneric.mg.61efcf81f3f4f09b
McAfeeArtemis!61EFCF81F3F4
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.1f3f4f
BitDefenderThetaGen:NN.ZexaF.34742.MnKfaKDNDfob
CyrenW32/Trojan.CLL.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Application.Graftor.792178
AvastFileRepPup [PUP]
Ad-AwareGen:Variant.Application.Graftor.792178
EmsisoftGen:Variant.Application.Graftor.792178 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Flyagent.tc
Trapminemalicious.high.ml.score
SophosGeneric PUA OD (PUA)
GDataWin32.Trojan.PSE.12RRE9
MAXmalware (ai score=76)
KingsoftWin32.Heur.KVM099.a.(kcloud)
ViRobotTrojan.Win32.Z.Graftor.1684992
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
VBA32BScope.Trojan.KillFiles
ALYacGen:Variant.Application.Graftor.792178
MalwarebytesMalware.AI.1376887679
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGFileRepPup [PUP]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.1376887679?

Malware.AI.1376887679 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment