Malware

Malware.AI.1518875800 removal tips

Malware Removal

The Malware.AI.1518875800 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1518875800 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the TYRAT malware family

How to determine Malware.AI.1518875800?


File Info:

name: 5A24F903472B09C45232.mlw
path: /opt/CAPEv2/storage/binaries/0e701d85049d2f364aea6df6bf9720ca3cff329740871402396a14eb542ee718
crc32: F2C87808
md5: 5a24f903472b09c4523205180ad63cc9
sha1: df40595b9241e92f0dd4fdadbd2de66188972c52
sha256: 0e701d85049d2f364aea6df6bf9720ca3cff329740871402396a14eb542ee718
sha512: 958ac498cf189661e8e33bd868dada48198297638d012db964edfaed51ef55ce40104091b93598276921c699f97ed671ed02e6a53097d9f8c8324e45d2789b5e
ssdeep: 6144:0vP7p+qPYEHb/Z1kO42CGfvopcjQn4V7J13kTFziEPc:suE0sLqcjYiEPc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFA48D1273D28073D4A613318F669378B7BABE11AC75860F67D0FB8E6E745028E25F25
sha3_384: f962aa5c195faf0f204289c7660e3df76c69bc97e9ba80fc973b81d8fb1701785deb281a5d37b989c3bbc549673f5e73
ep_bytes: e8c85d0000e916feffff6a00ff742414
timestamp: 2021-12-27 04:49:48

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: Jianfanwangshishou.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: Jianfanwangshishou.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Malware.AI.1518875800 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.60021482
FireEyeGeneric.mg.5a24f903472b09c4
McAfeeGenericRXGX-OX!5A24F903472B
CylanceUnsafe
SangforTrojan.Win32.Farfli.MA
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Kryptik.ce931060
K7GWRiskware ( 00584baa1 )
CyrenW32/Kryptik.EKE.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNYR
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.60021482
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.60021482
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PLU21
McAfee-GW-EditionGenericRXGX-OX!5A24F903472B
EmsisoftTrojan.GenericKD.60021482 (B)
GDataTrojan.GenericKD.60021482
JiangminHeur:TrojanDropper.TDSS
MAXmalware (ai score=82)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D393DAEA
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZexaF.34212.Cu0@a02XiOhj
ALYacTrojan.GenericKD.60021482
MalwarebytesMalware.AI.1518875800
TrendMicro-HouseCallTROJ_GEN.R002C0PLU21
RisingTrojan.Farfli!8.FF (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]

How to remove Malware.AI.1518875800?

Malware.AI.1518875800 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment