Trojan

Trojan.AntivmRI.S28491918 information

Malware Removal

The Trojan.AntivmRI.S28491918 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AntivmRI.S28491918 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.AntivmRI.S28491918?


File Info:

name: 49F782D86EB7D85C0C33.mlw
path: /opt/CAPEv2/storage/binaries/4959302ac47c1a48b4ae0502ac4109a15515b6b7d19b1f5735bc3e4a5e037492
crc32: D9CB6536
md5: 49f782d86eb7d85c0c3347ed760fd5bd
sha1: 7fb4783086ada0fd25197e0051977d48f74a6cc5
sha256: 4959302ac47c1a48b4ae0502ac4109a15515b6b7d19b1f5735bc3e4a5e037492
sha512: f8c00492a366accc0ff51a5f191c3d96af56ba16245d326728d8498b085a764a340f8911b50362fe4940b174bdc542a08e4597427276739d632c31924184aea0
ssdeep: 49152:7E2kFIAlDVIftUlls/aj0Qax5kaF1bVDXmal0RDm9iHWpYvVGIA80Iwq1uK:7wDVIftey35PF7malUyaWpgwI8G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DED533D6AE72C139C640823C8802AE2E97D4634702A29DF5FAD50F1FF35BD1E6658B4D
sha3_384: 95db10dc25d3b17b320ea8837544108b10cb575c29f1ae0c72c99db1e9f56cb9c1d6c2cb3e3de8d29d79c2ffcacf1a67
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2022-09-08 14:45:56

Version Info:

0: [No Data]

Trojan.AntivmRI.S28491918 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Convagent.trYj
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.GM.0000436180
FireEyeGeneric.mg.49f782d86eb7d85c
CAT-QuickHealTrojan.AntivmRI.S28491918
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058b2bf1 )
BitDefenderGen:Trojan.Heur.GM.0000436180
Cybereasonmalicious.86eb7d
CyrenW32/ClipBanker.AV.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Themida.IAN
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Trojanx-9917317-0
KasperskyHEUR:Trojan-Banker.Win32.Agent.pef
AlibabaPacked:Win32/Themida.859b0662
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Generic@AI.100 (RDML:ZpEhAswm8yaigMrkGjS9UQ)
Ad-AwareGen:Trojan.Heur.GM.0000436180
EmsisoftGen:Trojan.Heur.GM.0000436180 (B)
VIPREGen:Trojan.Heur.GM.0000436180
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Themida
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Heur.GM.D6A7D4
GDataWin32.Trojan-Stealer.Clipper.SF0HUE
GoogleDetected
AhnLab-V3Trojan/Win.ClipBanker.C4763551
Acronissuspicious
BitDefenderThetaAI:Packer.DD91A5B51D
ALYacGen:Trojan.Heur.GM.0000436180
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.4262994558
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTROJ_GEN.R002H0CIP22
TencentWin32.Trojan-Banker.Agent.Dnhl
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AntivmRI.S28491918?

Trojan.AntivmRI.S28491918 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment