Malware

Should I remove “Malware.AI.1116667578”?

Malware Removal

The Malware.AI.1116667578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1116667578 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1116667578?


File Info:

name: 190F455AEBDA8036C2BF.mlw
path: /opt/CAPEv2/storage/binaries/055c512fee0364bb9dfcb9346ca79cc806765bde1bbcdd0b2ddcf43dc3246eac
crc32: FAF22C44
md5: 190f455aebda8036c2bfcae615e36a1d
sha1: 9699690b32ed265d5a9785e9e1ea71db79667aa0
sha256: 055c512fee0364bb9dfcb9346ca79cc806765bde1bbcdd0b2ddcf43dc3246eac
sha512: 21dea1cdfdb233dc03f3c571c2bae5b2c17b2f9195a5be42eebff575f660438970f1e147c6eae7776cc32d37ee72ec6d8b960afd2c565b1238461d552502781a
ssdeep: 192:qFpWyJhGGYYp4q5HIPjmLt2WSE/FW757EIHaaEMMee:I4yJ2Yp4q5gs4WSE/Fs1E9h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DEA289382ED55A73E37BCEB6C5F652C6FD24B1123D06D80D40EB47490863B96ECA1A1E
sha3_384: 0b73040b40b945eb974f86257bf0bf7e9ca6274750f1780d5a5607143f8c6a147046b6dfbd235f37e1a3d0ed925c6f26
ep_bytes: 558bec81ec3c08000053565733f656ff
timestamp: 2013-10-15 12:38:30

Version Info:

0: [No Data]

Malware.AI.1116667578 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.lY5V
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74346
FireEyeGeneric.mg.190f455aebda8036
McAfeeDownloader-FBVZ!190F455AEBDA
MalwarebytesMalware.AI.1116667578
VIPRETrojan.GenericKDZ.74346
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKDZ.74346
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.aebda8
BaiduWin32.Trojan-Downloader.Waski.k
VirITTrojan.Win32.Dnldr25.DFUG
CyrenW32/Upatre.MG.gen!Eldorado
SymantecDownloader.Upatre!gm
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Bavs-6804154-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
AlibabaTrojanDownloader:Win32/Upatre.bd22e9e7
NANO-AntivirusTrojan.Win32.DownLoad3.cnbuup
AvastWin32:Downloader-WID [Trj]
TencentTrojan.Win32.Delf.kg
EmsisoftTrojan.GenericKDZ.74346 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader25.56634
ZillyaDownloader.Waski.Win32.48119
TrendMicroTROJ_GEN.R002C0CAU23
McAfee-GW-EditionBehavesLike.Win32.Generic.mz
Trapminemalicious.high.ml.score
SophosTroj/Upatre-YW
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/Generic.azrzv
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLVirus/Win32.Expiro.imp
ArcabitTrojan.Generic.D1226A
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojan:Win32/Upatre.AMN!MTB
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.Generic.R534444
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36308.bqX@aCcnhldi
ALYacTrojan.GenericKDZ.74346
VBA32Trojan.Generic
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0CAU23
RisingDownloader.Agent!1.C06E (CLASSIC)
IkarusTrojan-Downloader.Win32.Waski
MaxSecureSpy.Zbot.wpvt
FortinetW32/Waski.A!tr
AVGWin32:Downloader-WID [Trj]
PandaTrj/Genetic.gen

How to remove Malware.AI.1116667578?

Malware.AI.1116667578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment