Malware

Malware.AI.1769658641 removal guide

Malware Removal

The Malware.AI.1769658641 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1769658641 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Malware.AI.1769658641?


File Info:

name: 057DED3A71EAE6AE872B.mlw
path: /opt/CAPEv2/storage/binaries/692fc355d8aca4668c55e21a30a0a41740271f84931dbe29cd93401fc6b9c849
crc32: 555D0F23
md5: 057ded3a71eae6ae872bb58d7286615d
sha1: e3ff1cddb1f6deda7395041f7d39b7d80c3e2cd8
sha256: 692fc355d8aca4668c55e21a30a0a41740271f84931dbe29cd93401fc6b9c849
sha512: df02815aa85ab37474837f3b7debe3823cd3f28f9ea190f6cd2483a240e718aec6d9b7fcf29a0e6cf45f01cd0b31c41d7d4dd6bd4a7a21afeb00b18166065967
ssdeep: 12288:62ghLvPhXpe3Pl5nb4Yta7oriDsnqcH/LrvVyMNjW:6XhZgPlWcWsq+DW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134F49DA1A1C241F3CE71523FF861765311609E605F5A8EEF9E49B3198AFD6C234A8F1C
sha3_384: 0fe44d3fddbe8e7938e3e67d3109335f8253bb00b47b9b83e6923a274816c9bffd7904c5b6b0136b27d2c3ad5629b95b
ep_bytes: e89a040000e98efeffff3b0dc8a14300
timestamp: 2019-02-24 19:03:26

Version Info:

0: [No Data]

Malware.AI.1769658641 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Ciusky.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Ciusky-9819217-0
McAfeeArtemis!057DED3A71EA
CylanceUnsafe
SangforTrojan.Win32.Wacatac.C
BitDefenderTrojan.Ciusky.Gen.6
Cybereasonmalicious.a71eae
ArcabitTrojan.Ciusky.Gen.6
SymantecTrojan.Gen.MBT
CynetMalicious (score: 100)
KasperskyPDM:HEUR:Trojan.Win32.Bingo.gen
AlibabaTrojan:VBS/Redcap.43949918
MicroWorld-eScanTrojan.Ciusky.Gen.6
Ad-AwareTrojan.Ciusky.Gen.6
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.ruzym
VIPRETrojan.Ciusky.Gen.6
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.057ded3a71eae6ae
APEXMalicious
AviraTR/Redcap.ruzym
MicrosoftTrojan:Win32/Ymacco.AA69
ZoneAlarmPDM:HEUR:Trojan.Win32.Bingo.gen
GDataTrojan.Ciusky.Gen.6
ALYacTrojan.Ciusky.Gen.6
MalwarebytesMalware.AI.1769658641
IkarusTrojan.Ciusky
TencentWin32.Trojan.Bingo.Eor
MAXmalware (ai score=88)
MaxSecureTrojan.Malware.108560821.susgen
Paloaltogeneric.ml

How to remove Malware.AI.1769658641?

Malware.AI.1769658641 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment