Malware

Malware.AI.1776398684 (file analysis)

Malware Removal

The Malware.AI.1776398684 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1776398684 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.1776398684?


File Info:

name: 4C350A676865B314D2EE.mlw
path: /opt/CAPEv2/storage/binaries/0d0540f014048d8a25dd61097855b32435d8570cd5c7d1aa9f24b2b463ea0289
crc32: 9C032013
md5: 4c350a676865b314d2ee34d553438c07
sha1: 5675e4448f82ef92523a7944c835d52bd2da46eb
sha256: 0d0540f014048d8a25dd61097855b32435d8570cd5c7d1aa9f24b2b463ea0289
sha512: 9716740d97f77b0a3d7407e3201ccc30e1a72564efe4b9a0d93c9f2fd87162d977da4fb0491483f28a016f55aa4a4ab69af883f1453bf8aaf92b9ed659a38157
ssdeep: 384:YfbpN953/xQuqNlhaSZoU/3zQJQzKjrAuFosLk24jXPlLaoe/SYHvday9W:WxKDoeDQJQzKduA2XPTB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CAD2512712DEBEE2C8B91670377343C1D36DEE055503DA2E99D0752ADA7E2037A823D9
sha3_384: aaa747547294ca5fa9f96f68994eb4c6b2ea2be23f4371e08d7b4ad52684b5c648af213bda878eda3e9d9fa49523659a
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-06-04 22:10:12

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Loader
FileVersion: 1.0.0.0
InternalName: Loader.exe
LegalCopyright: Copyright © 2015
OriginalFilename: Loader.exe
ProductName: Loader
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.1776398684 also known as:

BkavW32.Common.7C62777B
LionicTrojan.Win32.Generic.4!c
SkyhighArtemis!Trojan
McAfeeArtemis!4C350A676865
Cylanceunsafe
ZillyaDownloader.Small.Win32.221569
SangforDownloader.Msil.Small.Vhki
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan-Downloader ( 005ab5db1 )
K7AntiVirusTrojan-Downloader ( 005ab5db1 )
BitDefenderThetaGen:NN.ZemsilF.36680.bq0@amBjfRk
ESET-NOD32MSIL/TrojanDownloader.Small.DAK
APEXMalicious
CynetMalicious (score: 99)
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13f64d8a
SophosMal/Generic-R
F-SecureHeuristic.HEUR/AGEN.1308088
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1308088
Antiy-AVLTrojan[Downloader]/MSIL.Small
Kingsoftmalware.kb.c.778
MalwarebytesMalware.AI.1776398684
TrendMicro-HouseCallTROJ_GEN.R002H0AGK23
RisingDownloader.Small!8.B41 (CLOUD)
IkarusTrojan-Downloader.MSIL.Small
MaxSecureTrojan.Malware.216064600.susgen
FortinetMSIL/Small.DAK!tr.dldr
AVGWin32:Malware-gen
Cybereasonmalicious.48f82e
DeepInstinctMALICIOUS

How to remove Malware.AI.1776398684?

Malware.AI.1776398684 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment