Malware

Malware.AI.1736661414 removal

Malware Removal

The Malware.AI.1736661414 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1736661414 virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

Related domains:

wpad.local-net

How to determine Malware.AI.1736661414?


File Info:

name: 10C70017D7A17B3B9B68.mlw
path: /opt/CAPEv2/storage/binaries/974faba91f31921b1391870d2221f2ac66d2b8373f461e39eb09d397da5fb70a
crc32: D3AE0101
md5: 10c70017d7a17b3b9b68562990526d5e
sha1: 90791cd2b8e00a732b38d84ea03531b93df95041
sha256: 974faba91f31921b1391870d2221f2ac66d2b8373f461e39eb09d397da5fb70a
sha512: 213c2f3e47d62698e602a098c49b6d069ad23441e6346e02ca688800e8a33ff0d62858f467c40bea10b047a6f5885007635f72c5739fc4f921d3699b08cd4907
ssdeep: 49152:5JsV6llQYegZO3hauHXfjflg/9b0qowg7NFf/J:5JsVilQYegdu3fTlglA1wSNZ
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T15095236D7BDC6E1EC0D4533F308616D266BBDA28F599EF46A40F59F43E933248E1108A
sha3_384: 534d88164af4f9914cb0967e889406c8b344655becf66d15d9f2ca54b9e0f18da38c0b63c6e059b015c2c3aa8b83382d
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2082-11-08 20:13:28

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ICU
FileVersion: 1.0.0.0
InternalName: ICU.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: ICU.exe
ProductName: ICU
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.1736661414 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47462278
FireEyeGeneric.mg.10c70017d7a17b3b
CylanceUnsafe
K7GWTrojan ( 00574e2d1 )
K7AntiVirusTrojan ( 00574e2d1 )
ESET-NOD32a variant of MSIL/Packed.VMProtect.C suspicious
APEXMalicious
KasperskyHEUR:Trojan-Dropper.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.47462278
AvastWin64:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.47462278
SophosML/PE-A
EmsisoftTrojan.GenericKD.47462278 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47462278
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1141199
ArcabitTrojan.Generic.D2D43786
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
MAXmalware (ai score=88)
MalwarebytesMalware.AI.1736661414
IkarusTrojan.MSIL.Vmprotect
MaxSecureTrojan.Malware.300983.susgen
AVGWin64:TrojanX-gen [Trj]
Cybereasonmalicious.2b8e00
PandaTrj/Orbond.A

How to remove Malware.AI.1736661414?

Malware.AI.1736661414 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment