Malware

Malware.AI.1825511268 removal tips

Malware Removal

The Malware.AI.1825511268 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1825511268 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Detects Avast Antivirus through the presence of a library

How to determine Malware.AI.1825511268?


File Info:

name: 17C7093634260E03A5A5.mlw
path: /opt/CAPEv2/storage/binaries/37438a295c7c6e0b2b266121553621e26d357f7a3a25de267eae40a97e9556c4
crc32: 1832FAC7
md5: 17c7093634260e03a5a5a6ac679ad236
sha1: fabe220167600fc4617eafe96ba08a954d6a5caa
sha256: 37438a295c7c6e0b2b266121553621e26d357f7a3a25de267eae40a97e9556c4
sha512: 626e728bcaad4c6d0086c79a515dd259cace84fb4c678b469f81e7f11de8ece6050f0f524da688a9ab927ddb922af2edc0f37f054d659c31d39fb5043b091b66
ssdeep: 768:NkxG8TD5661Knuh+Xc99cnqhduy+1zYcHe+m:OJ661Uul99cnadwU+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172F25C815B8CC33FCBAE0B3598B2612543F1E58F1616EB2ABDD8769A3B5778442104F5
sha3_384: 193fac98809bc1859b0c5b9634a7333351f771711239365cff5e6d0159c3a46b3aad6889adef52d209c9b3794559612e
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-08-03 15:15:18

Version Info:

Translation: 0x0000 0x04b0
FileDescription: SafeguardUninstaller
FileVersion: 0.0.0.0
InternalName: SafeguardUninstaller.exe
LegalCopyright: Copyright © 2015
OriginalFilename: SafeguardUninstaller.exe
ProductName: SafeguardUninstaller
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Malware.AI.1825511268 also known as:

LionicAdware.MSIL.Agent.2!c
MicroWorld-eScanAdware.Generic.3005710
FireEyeGeneric.mg.17c7093634260e03
CAT-QuickHealTrojan.Agent
ALYacAdware.Generic.3005710
CylanceUnsafe
ZillyaAdware.GenericKD.Win32.5312
SangforTrojan.Win32.Gen.2
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:MSIL/Wajam.39283da3
K7GWAdware ( 004e5b5b1 )
K7AntiVirusAdware ( 004e5b5b1 )
CyrenW32/Trojan.SMYB-0975
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.Wajam.G
APEXMalicious
Kasperskynot-a-virus:AdWare.MSIL.Agent.adkb
BitDefenderAdware.Generic.3005710
NANO-AntivirusRiskware.Win32.Wajam.ixvxvg
SUPERAntiSpywarePUP.Wajam/Variant
TencentMsil.Adware.Wajam.Eadz
Ad-AwareAdware.Generic.3005710
SophosGeneric PUA PK (PUA)
ComodoApplication.MSIL.Wajam.AC@6l2q9c
TrendMicroTROJ_GEN.R002C0WJS21
McAfee-GW-EditionArtemis
EmsisoftAdware.Generic.3005710 (B)
SentinelOneStatic AI – Malicious PE
GDataAdware.Generic.3005710
JiangminAdWare.MSIL.nldg
eGambitUnsafe.AI_Score_99%
AviraADWARE/Wajam.rdqme
Antiy-AVLTrojan/Generic.ASMalwS.3476A26
ViRobotAdware.Wajam.35840.F
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
AhnLab-V3Adware/Win32.Agent.R217435
McAfeeArtemis!17C709363426
MAXmalware (ai score=61)
VBA32AdWare.MSIL.Agent
MalwarebytesMalware.AI.1825511268
TrendMicro-HouseCallTROJ_GEN.R002C0WJS21
IkarusPUA.Wajam
MaxSecureTrojan.Malware.119844374.susgen
FortinetMSIL/Generic_PUA_PK.G

How to remove Malware.AI.1825511268?

Malware.AI.1825511268 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment