Malware

Malware.AI.2766163063 removal instruction

Malware Removal

The Malware.AI.2766163063 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2766163063 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Harvests cookies for information gathering

How to determine Malware.AI.2766163063?


File Info:

name: 53C0EA74EFB1B2B2AB1B.mlw
path: /opt/CAPEv2/storage/binaries/66aad2b35dceb2e55ab53f27c0d27f66a37ebd4724046cce2c5ae7de30cff656
crc32: 74ADBA33
md5: 53c0ea74efb1b2b2ab1bebf2a190b5f0
sha1: e849a997469486be7e9966f9feea655c87993a2c
sha256: 66aad2b35dceb2e55ab53f27c0d27f66a37ebd4724046cce2c5ae7de30cff656
sha512: 004deac7b1c99797d773b0c7f82a0c5e61c2229170a5d5c9265ce7c4771d8c39f19978245da726e1217f173bb62f9fea17f9a43cadecc73e4aa73b34b76192f5
ssdeep: 24576:dQ9oopnfCD3JN//P+gwAoOtSMgXPp9axGWn/25Gr8/14/9RQh5eWPcP6q:dQZpqD3X/+gfoESMgfp9aju88y/9RQ+1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1353523C547AA846AFEF2183C7AA642612E2FFED7B872711E47E8760C67332051590773
sha3_384: 79676d4287436d7be4746a8963331a97f5487065c7f2d83878e911f0c31763a49586be2b4a21111027bf1c39f03f8c4b
ep_bytes: 558bec6aff682821400068a01e400064
timestamp: 2011-01-31 17:44:13

Version Info:

LegalCopyright: Copyright (C) 2010 Valve Corporation
InternalName: steamcmd
FileVersion: 1, 0, 0, 1
CompanyName: Valve Corporation
ProductVersion: 1, 0, 0, 1
FileDescription: Steam Client Bootstrapper
Source Control ID: 5361640
OriginalFilename: steam.exe
ProductName: Steam Client Bootstrapper
Translation: 0x0409 0x04b0

Malware.AI.2766163063 also known as:

LionicTrojan.Win32.Miner.4!c
MicroWorld-eScanTrojan.GenericKD.43675317
FireEyeTrojan.GenericKD.43675317
ALYacTrojan.GenericKD.43675317
CylanceUnsafe
SangforTrojan.XML.Agent.AN
BitDefenderTrojan.GenericKD.43675317
SymantecML.Attribute.HighConfidence
ESET-NOD32XML/Agent.AN
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
KasperskyTrojan.Win32.Miner.assaj
AlibabaTrojan:Win32/Miner.66d41063
NANO-AntivirusTrojan.Win32.Miner.imxjsf
RisingTrojan.Generic@ML.80 (RDMK:hY/eGZQKVVku2BurVx+I2g)
Ad-AwareTrojan.GenericKD.43675317
EmsisoftTrojan.GenericKD.43675317 (B)
DrWebTrojan.BtcMine.3456
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S
IkarusTrojan.XML.Agent
APEXMalicious
GDataTrojan.GenericKD.43675317
CynetMalicious (score: 100)
McAfeeArtemis!53C0EA74EFB1
VBA32Trojan.Miner
MalwarebytesMalware.AI.2766163063
TencentTrojan.Win32.BitCoinMiner.la
WebrootW32.Trojan.Coinminer
AVGWin32:Malware-gen
Cybereasonmalicious.4efb1b
AvastWin32:Malware-gen

How to remove Malware.AI.2766163063?

Malware.AI.2766163063 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment