Malware

Malware.AI.1177068292 removal instruction

Malware Removal

The Malware.AI.1177068292 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1177068292 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.1177068292?


File Info:

crc32: 64E1F2C5
md5: 0afd349888ad68156114bdd75f80f24b
name: 0AFD349888AD68156114BDD75F80F24B.mlw
sha1: 72d73a0bedfa9f9a45571c2b3a2ebf6c0d273d83
sha256: 055a4d02c3999a5f8d7291fd70882cf6bce36008120191017419ae391283ff7b
sha512: 68ab305a6f9884b1fc2dea27d1e3e28eeaf0bfe6ccf887dfaa29dfeac03c909f570466f628ea37c6e92c0b63fd8c25acbe5bc2a58eb5b600ad28230b4bf26cf5
ssdeep: 24576:GJdivjECColLNf+wpOxxbcoCALfQ3SveeMHXj5jd6QknFI5:gdSHN+XveeMHTn6QkF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2015
Assembly Version: 1.0.0.0
InternalName: LittleEngine.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: LittleEngine
ProductVersion: 1.0.0.0
FileDescription: LittleEngine
OriginalFilename: LittleEngine.exe

Malware.AI.1177068292 also known as:

K7AntiVirusTrojan ( 0056e6811 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.652233
CylanceUnsafe
SangforTrojan.Win32.Malware.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaPacked:Win32/VMProtect.3212f460
K7GWTrojan ( 0056e6811 )
Cybereasonmalicious.888ad6
CyrenW32/S-37c4fc7a!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.ABR
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Ursu.652233
NANO-AntivirusTrojan.Win32.Black.dzekyp
MicroWorld-eScanGen:Variant.Ursu.652233
TencentWin32.Trojan.Black.Jmr
Ad-AwareGen:Variant.Ursu.652233
SophosMal/Generic-R + Mal/VMProtBad-A
ComodoMalware@#28zilamfiuaf0
BitDefenderThetaAI:Packer.467155A31D
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RHM21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.0afd349888ad6815
EmsisoftGen:Variant.Ursu.652233 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Black.Gen2
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Ursu.652233
Acronissuspicious
McAfeeArtemis!0AFD349888AD
MAXmalware (ai score=88)
VBA32Trojan.Skeeyah
MalwarebytesMalware.AI.1177068292
TrendMicro-HouseCallTROJ_GEN.R002C0RHM21
RisingTrojan.Generic@ML.100 (RDML:34dpFi7NRRzMq6gy9xbaMQ)
YandexTrojan.GenAsa!tdadYUDy5l4
IkarusTrojan.MSIL.MultiPacked
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VMProtBad.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1177068292?

Malware.AI.1177068292 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment