Malware

Malware.AI.1876933768 removal instruction

Malware Removal

The Malware.AI.1876933768 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1876933768 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Malware.AI.1876933768?


File Info:

name: C603CDFFCADDA4447D25.mlw
path: /opt/CAPEv2/storage/binaries/7894eaae5013cb7d1eb6e3c2dfdc264d4b59a559632c161cbe7c7d53419d254f
crc32: A4D80A27
md5: c603cdffcadda4447d25f8876f0a9210
sha1: 761810dd573c836deb6b0d0e06a53c13c1b4a9d4
sha256: 7894eaae5013cb7d1eb6e3c2dfdc264d4b59a559632c161cbe7c7d53419d254f
sha512: 0b1b116e61a803b216dfd7185e1e180a52490b88ac444168c1bb79938e85a168d7f9cb964433c1849a6804a7324fb20dc784fb272224d99855d3e16f4e73aa4a
ssdeep: 768:5ZidDabL0sXYqhedYPUs81U2FAT9xD6qSa4hueDAGuo9sha:5UdDabL0sXYqSWGFAXD6qSa4xDL3ss
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B903F1EB31C8226EEFD08B3D416F6D5366293918959E42E7A23C2D776D32AD534080DE
sha3_384: f95d698a985d7f57454352adb7be33b93fff5adaffc4ea4ac17e73b0f4a35cf6fe2bf11e0968f1efd8826687e2716975
ep_bytes: 60be002041008dbe00f0feff57eb0b90
timestamp: 2008-12-03 12:32:17

Version Info:

0: [No Data]

Malware.AI.1876933768 also known as:

LionicTrojan.Win32.Agent.a!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.3126104
FireEyeGeneric.mg.c603cdffcadda444
ALYacTrojan.Generic.3126104
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Dloadr.631760e5
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
VirITTrojan.Win32.Generic.GLK
CyrenW32/Downloader.BKJB-3868
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Agent.OOJ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.62583-1
KasperskyTrojan-Downloader.Win32.Agent.ayxc
BitDefenderTrojan.Generic.3126104
NANO-AntivirusTrojan.Win32.Agent.dwrcpj
ViRobotTrojan.Win32.Downloader.38486
AvastWin32:Trojan-gen
RisingTrojan.DL.Win32.Mnless.btd (CLASSIC)
Ad-AwareTrojan.Generic.3126104
EmsisoftTrojan.Generic.3126104 (B)
ComodoTrojWare.Win32.Downloader.Small.ai17@1ozpgg
DrWebTrojan.DownLoad.23641
ZillyaDownloader.Agent.Win32.43
TrendMicroTROJ_AGENT.AGCU
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Troj/Dloadr-CQP
IkarusTrojan-Dropper.Agent
GDataTrojan.Generic.3126104
JiangminTrojanDownloader.Agent.anvw
WebrootW32.Malware.Downloader
AviraTR/Downloader.Gen
MAXmalware (ai score=100)
KingsoftWin32.Heur.KVMH017.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.AB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C43195
Acronissuspicious
McAfeegeneric!bg.f
TACHYONTrojan-Downloader/W32.Agent.86608
VBA32Trojan.Downloader.2713
MalwarebytesMalware.AI.1876933768
TrendMicro-HouseCallTROJ_AGENT.AGCU
TencentMalware.Win32.Gencirc.10b74ede
YandexTrojan.GenAsa!VzFIP2TWewE
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.AXC!tr.dldr
BitDefenderThetaAI:Packer.BB54D96D1D
AVGWin32:Trojan-gen
Cybereasonmalicious.fcadda
PandaGeneric Malware

How to remove Malware.AI.1876933768?

Malware.AI.1876933768 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment