Malware

Malware.AI.602884076 information

Malware Removal

The Malware.AI.602884076 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.602884076 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.602884076?


File Info:

name: C843A8AF547C434F8C38.mlw
path: /opt/CAPEv2/storage/binaries/b1fa0c3d7b96f0c572f2deda6d3db284aaecbaae7e4a2cd9c4ff447c6ac50d6c
crc32: 69BCA7F3
md5: c843a8af547c434f8c3818d975c85a1c
sha1: 4ac7aca48055f571ff366a47653be4146dc50a1c
sha256: b1fa0c3d7b96f0c572f2deda6d3db284aaecbaae7e4a2cd9c4ff447c6ac50d6c
sha512: 3a264b7588ffe131ae2847f8731283cc6af50f59690946d0fcc602ff43c6da17b3934bc1423bf867be759489ec715b6b3ec22e64016d42142b5e5506fc5da11d
ssdeep: 6144:RqtykYGtS5LoCBap4kNKJXx0obFmOz7h0o5:xkA8mapuJ/bsm5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T110A43A369BA62BA2D636247C184A37CD5D28F0882FD4EB5AF34E3E645B351111CFE6C1
sha3_384: 7b5c795cef0b3b8cfadc69d5be69e5b443cf0d72636e799a6ac37519f40234184ae798476683f7ba15933fc780ef49b4
ep_bytes: 558bec6aff684031400068b022400064
timestamp: 2011-03-15 04:06:07

Version Info:

0: [No Data]

Malware.AI.602884076 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.185
CynetMalicious (score: 100)
FireEyeGeneric.mg.c843a8af547c434f
CAT-QuickHealW32.Zombie.A4
ALYacTrojan.GenericKD.34110279
CylanceUnsafe
ZillyaTrojan.Cosmu.Win32.12187
K7AntiVirusTrojan ( 0055e3dd1 )
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.f547c4
ArcabitTrojan.Generic.D2087B47
BitDefenderThetaGen:NN.ZexaF.34182.DqZ@aGBV9uib
CyrenW32/Cosmu.H.gen!Eldorado
ESET-NOD32Win32/Agent.NBJ
TrendMicro-HouseCallTROJ_SPNR.15CC13
ClamAVWin.Trojan.Cosmu-1058
KasperskyTrojan.Win32.Cosmu.bwts
BitDefenderTrojan.GenericKD.34110279
NANO-AntivirusTrojan.Win32.Cosmu.bgzaxj
MicroWorld-eScanTrojan.GenericKD.34110279
AvastWin32:RansomX-gen [Ransom]
TencentVirus.Win32.Cosmu.a
Ad-AwareTrojan.GenericKD.34110279
EmsisoftTrojan.GenericKD.34110279 (B)
ComodoTrojWare.Win32.Agent.NBJ@4xjtww
VIPRETrojan.Win32.Cosmu.bwts (v)
TrendMicroTROJ_SPNR.15CC13
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.gh
SophosMal/Behav-112
IkarusTrojan.Win32.Cosmu
JiangminTrojan/Cosmu.ppf
AviraTR/ATRAPS.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.13CA44
KingsoftHeur.SSC.2787082.0010.(kcloud)
MicrosoftTrojan:Win32/Zombie.A
ZoneAlarmTrojan.Win32.Cosmu.bwts
GDataTrojan.GenericKD.34110279
AhnLab-V3Trojan/Win32.Cosmu.R51515
McAfeeGenericRXNR-SA!C843A8AF547C
VBA32Trojan.Cosmu
MalwarebytesMalware.AI.602884076
APEXMalicious
RisingTrojan.Zombie!8.2DA5 (RDMK:cmRtazqZA6YRCTDRdADX/kB5jVbL)
YandexTrojan.GenAsa!qZCC7vZoV+4
MaxSecureTrojan.Cosmu.bwts
FortinetW32/Agent.NBJ!tr
AVGWin32:RansomX-gen [Ransom]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.602884076?

Malware.AI.602884076 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment