Malware

Should I remove “Malware.AI.1809573986”?

Malware Removal

The Malware.AI.1809573986 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1809573986 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Malware.AI.1809573986?


File Info:

name: D0B16E72D10E6892A808.mlw
path: /opt/CAPEv2/storage/binaries/6c7d69339c4bc925f8d56113395717b79f3453092d0ad20af39c5a3d6830ebed
crc32: 47F6A7DA
md5: d0b16e72d10e6892a808f97e54d54ee8
sha1: c119824f79241e115e5de8ec5684f579be5d8f54
sha256: 6c7d69339c4bc925f8d56113395717b79f3453092d0ad20af39c5a3d6830ebed
sha512: 5b8af4873bc200faf52ad178d88883cd24ddec9895fdd1baa534fce35940ece4f0851edcd95451d40b15bfd3cc1e7eaf742d49e4fc0085f3684ddacbf3503aad
ssdeep: 24576:lMrpqE/w76aMwCwuaFm8TwoOBkr6Ud/ehNtaPL2bYOmV4bczOcWvmQTI:lE0576aGZaFm80E6UtVSrWmC5WuQM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18895330FF3F60363DB73C43A182B9E4A66406F4C98956A77E91D61DDCAB0E13528E522
sha3_384: f369e856e9b2d4f3e0c5633990b1f5999df27e6a14805d4e9a0c4afa4770b1f4b0216297a9432279f201e9e274131384
ep_bytes: 60be001056008dbe0000eaff57eb0b90
timestamp: 2015-10-23 09:32:22

Version Info:

FileVersion: 1.0.0.0
InternalName: Launcher.exe
OriginalFilename: Launcher.exe
ProductVersion: 1.0.0.0
Translation: 0x0804 0x03a8

Malware.AI.1809573986 also known as:

LionicTrojan.Win32.Fugrafa.4!c
MicroWorld-eScanGen:Variant.Fugrafa.135433
FireEyeGeneric.mg.d0b16e72d10e6892
McAfeeArtemis!D0B16E72D10E
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusAdware ( 005693e61 )
K7GWAdware ( 005693e61 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/XYLauncher.B potentially unwanted
Paloaltogeneric.ml
BitDefenderGen:Variant.Fugrafa.135433
SophosGeneric PUA MB (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftGen:Variant.Fugrafa.135433 (B)
JiangminTrojan.Generic.hedca
eGambitUnsafe.AI_Score_65%
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Fugrafa.135433
CynetMalicious (score: 100)
MAXmalware (ai score=83)
VBA32Trojan.Tiggre
MalwarebytesMalware.AI.1809573986
TrendMicro-HouseCallTROJ_GEN.R002H09AK22
FortinetRiskware/XYLauncher
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.1809573986?

Malware.AI.1809573986 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment