Malware

Malware.AI.1160291973 (file analysis)

Malware Removal

The Malware.AI.1160291973 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1160291973 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Malware.AI.1160291973?


File Info:

name: 1BDA64BF2C678EAAD134.mlw
path: /opt/CAPEv2/storage/binaries/0a7209e75f0c848e5825afd971f94d05ea0c5c9da092f715749e7e9c6b3d7092
crc32: 31A49899
md5: 1bda64bf2c678eaad134d85cee5411a0
sha1: d752ee0780b1aa488860dadc394e7a743e2f7df0
sha256: 0a7209e75f0c848e5825afd971f94d05ea0c5c9da092f715749e7e9c6b3d7092
sha512: ce6ea89c88335a9be1813a0cb37dbac60e5629ba9674058bf2bf754c564659a6e93a42619a86a88e7625232d82794598e27dc99b51786790de6d5fc7a0ceffb3
ssdeep: 1536:Q7wVFjboxTUBtizWywMsK8q72QNSqxAASKrSitUrN4oQ/hKeXsjEFf3:QgDBtiJ772QNPPSK24oQZiEJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103D3E5293291E23ED419CBF42E1A83E490ADAC3521D6B81BF7C55B1273F2D578360B53
sha3_384: 69e7029251dadcaa0fb5ba6764fa1b2c06ebd29d7e67fe07de0e1e868e1d05e4f0cd8a4554a88de25fad28bab9ec473c
ep_bytes: 68cc324000e8f0ffffff000000000000
timestamp: 1995-08-10 23:46:21

Version Info:

Translation: 0x0409 0x04b0
ProductName: bCtvzIUboYl
FileVersion: 1.00
ProductVersion: 1.00
InternalName: jHLXutCT
OriginalFilename: jHLXutCT.exe

Malware.AI.1160291973 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.60
MicroWorld-eScanGen:Trojan.Sresmon.Gen.1
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Vobfus.gen
McAfeeVBObfus.eq
MalwarebytesMalware.AI.1160291973
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 002de3871 )
AlibabaWorm:Win32/Vobfus.a781ac51
K7GWP2PWorm ( 002de3871 )
Cybereasonmalicious.f2c678
BitDefenderThetaAI:Packer.715549FB1F
VirITTrojan.Win32.Generic.BIRQ
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup!gen35
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.AFV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.ernd
BitDefenderGen:Trojan.Sresmon.Gen.1
NANO-AntivirusTrojan.Win32.Scar.cniokg
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
EmsisoftGen:Trojan.Sresmon.Gen.1 (B)
F-SecureWorm.WORM/Vobus.N.4
BaiduWin32.Worm.Pronny.d
VIPREGen:Trojan.Sresmon.Gen.1
TrendMicroWORM_VOBFUS.SMHE
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1bda64bf2c678eaa
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10I69CR
AviraWORM/Vobus.N.4
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Diple.EMIB@4pez3w
ArcabitTrojan.Sresmon.Gen.1
ViRobotTrojan.Win32.A.Scar.135168
ZoneAlarmTrojan.Win32.Scar.ernd
MicrosoftWorm:Win32/Vobfus.gen!N
GoogleDetected
AhnLab-V3Trojan/Win32.HDC.C127440
VBA32BScope.Trojan.Diple
MAXmalware (ai score=80)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C7 (CLASSIC)
IkarusWorm.Win32.WBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1160291973?

Malware.AI.1160291973 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment