Malware

About “Malware.AI.1918505499” infection

Malware Removal

The Malware.AI.1918505499 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1918505499 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.1918505499?


File Info:

name: 03C8E18BFDC08AD91BB0.mlw
path: /opt/CAPEv2/storage/binaries/f496834f098423fafe5fc1d38d9f7e27430dc0d40918144408712c9285ad69b6
crc32: C83D82DF
md5: 03c8e18bfdc08ad91bb0cce5aeabbb80
sha1: 47d8bb7acc16c39d1485f4292352812aee20e786
sha256: f496834f098423fafe5fc1d38d9f7e27430dc0d40918144408712c9285ad69b6
sha512: e2124a38e5fdaaef8846f899412375e465181aa45dfaab8bda4b1e796fda241c33254316723588b60c02d91382421a4efdef4223f7b3fb8ee86365c6c0fbbc95
ssdeep: 24576:tCDXM/MjOXgvWxfWd/OvbJzoVvQI5a9/8Lk50FVCB5KIzLQRCh30e9xOf3Q2phXa:ytEk9Odoi/h0A4SkeLFsZK+AVpOEKJM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DC533B23295A134EA500DB5DB732394A21AB14581220ECF76D4BF6E5AFD730EB5CD8C
sha3_384: 70bce92a9b6ae05f39c82fe7889156c07f78108b75fabbc6026975ecb64e3d7dc963fc79408a6ec89f3e10a7721ccfaa
ep_bytes: eb08001e04000000000060e800000000
timestamp: 2015-11-18 00:24:28

Version Info:

0: [No Data]

Malware.AI.1918505499 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vimditator.j!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.71940202
FireEyeGeneric.mg.03c8e18bfdc08ad9
SkyhighBehavesLike.Win32.Generic.vc
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0058c50b1 )
K7GWTrojan ( 0058c50b1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.AMX@ayOPikji
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win64/Packed.Enigma.CE
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.pef
NANO-AntivirusTrojan.Win32.Vimditator.kktcvz
TencentMalware.Win32.Gencirc.10bfbfd0
F-SecureTrojan.TR/Vimditator.roaur
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Vimditator.roaur
MAXmalware (ai score=80)
Antiy-AVLTrojan[Packed]/Win64.Enigma
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.pef
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5600926
MalwarebytesMalware.AI.1918505499
RisingTrojan.Vimditator!8.1DAF (TFE:4:1VvZdbZK26D)
YandexTrojan.Enigma!zEb9Cgy+H7M
IkarusTrojan.Win64.Enigma
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Packed.EnigmaProtector.Z(dyn)

How to remove Malware.AI.1918505499?

Malware.AI.1918505499 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment