Trojan

Trojan.AntiavRI.S17248112 removal

Malware Removal

The Trojan.AntiavRI.S17248112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AntiavRI.S17248112 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system

How to determine Trojan.AntiavRI.S17248112?


File Info:

name: 26836E6765A61CB21E0A.mlw
path: /opt/CAPEv2/storage/binaries/493ec5bfb2c20e240851402d3ad7585806ea5d4aacff3af0e955df5e62e0bf94
crc32: D584EFCE
md5: 26836e6765a61cb21e0a244a6c833620
sha1: 5178268b4e9aab468037ee80143895f3daf092a4
sha256: 493ec5bfb2c20e240851402d3ad7585806ea5d4aacff3af0e955df5e62e0bf94
sha512: 0056c3fce4c40abd066a7493f2f31d793163c2b61c9407ce2781eec4b8eb568da66aff9663d743c3c97d19ccde60af92eca85102a05be5b45da9e178d2e2c181
ssdeep: 98304:UN+rQ2YmwQ9R+6+677zwsGiXGw66DkNZ:FE6nR+6731Gi2gA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2063327B568C5F5C904D33D8AD896D89FBDAE0322C3205267AB39BE5B50587F80E1C9
sha3_384: 8d491e707d4ee220281f6a0c51151f70eb0986c0e7796277f56d266c2f0c3307494c37680f82633479f17c0f75b03913
ep_bytes: e8b4250000e979feffff8bff558bec8b
timestamp: 2020-04-19 01:35:48

Version Info:

0: [No Data]

Trojan.AntiavRI.S17248112 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.AntiAV.4!c
tehtrisGeneric.Malware
DrWebTrojan.Siggen11.15778
MicroWorld-eScanTrojan.GenericKD.44501328
FireEyeGeneric.mg.26836e6765a61cb2
CAT-QuickHealTrojan.AntiavRI.S17248112
ALYacTrojan.GenericKD.44501328
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003c36381 )
AlibabaTrojan:Win32/Glupteba.1abffde6
K7GWTrojan ( 003c36381 )
Cybereasonmalicious.765a61
BitDefenderThetaGen:NN.ZexaF.34606.UtW@aSVqcwmO
CyrenW32/Wacatac.CH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HHME
TrendMicro-HouseCallBackdoor.Win32.GLUPTEBA.SMTH.hp
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.AntiAV.pef
BitDefenderTrojan.GenericKD.44501328
NANO-AntivirusTrojan.Win32.AntiAV.ibwofa
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.11b2af11
Ad-AwareTrojan.GenericKD.44501328
EmsisoftTrojan.GenericKD.44501328 (B)
F-SecureTrojan.TR/AD.GoCloudnet.brl
ZillyaTrojan.AntiAV.Win32.13480
TrendMicroBackdoor.Win32.GLUPTEBA.SMTH.hp
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.wc
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
GDataTrojan.GenericKD.44501328
JiangminTrojan.AntiAV.drw
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.brl
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.30FFBB6
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D2A70950
MicrosoftTrojan:Win32/Glupteba.MI!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPe.R353924
Acronissuspicious
McAfeeLockbit-FSUC!26836E6765A6
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingMalware.Obscure!1.A3BB (CLOUD)
YandexTrojan.AntiAV!6pjmo0Uny28
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1384705.susgen
FortinetW32/GenKryptik.EWTP!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AntiavRI.S17248112?

Trojan.AntiavRI.S17248112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment