Malware

Malware.AI.1178432061 (file analysis)

Malware Removal

The Malware.AI.1178432061 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1178432061 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.1178432061?


File Info:

name: 8191BE6F5AD9E8B2ABC0.mlw
path: /opt/CAPEv2/storage/binaries/62d45a9b6be0563a15a206f86c7dd21d861cc5255040a4f339d8786978bfa0c4
crc32: ABB18897
md5: 8191be6f5ad9e8b2abc0d24b6cd6bb6e
sha1: f2ec456c043c0c588cf116e5917f3e48289b1019
sha256: 62d45a9b6be0563a15a206f86c7dd21d861cc5255040a4f339d8786978bfa0c4
sha512: 949ba6d47ef4efad73cd37c4d1f90b0ad7a489b7ed81f885353d1f19c339e6c98af5cfc4b6af23919d68a3ced662dbd41cfd623fc3052cfe1cb9a35250e75f78
ssdeep: 6144:YUBOU3EiMAG6DqwuNAmzw+dNmry7iPNkuQa2IvQt60uwcmgjxi4L4b1xDeh:YkLMAEwKAxy7m3Q7IvQc0imgjx74bnE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AD947C78D6142DCCF53F7F3838D9B59099542F63321AA422ACEF585906F8BBA4378583
sha3_384: 735dafa589beea4f285e64583613848563a3d166a0af005b311ae78453aa1bd22cbf27308fd599e635f54683df1b1417
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2070-05-17 21:31:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: x86 Performance Counter Host
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: perfhost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: perfhost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Malware.AI.1178432061 also known as:

Elasticmalicious (high confidence)
DrWebWin32.Expiro.150
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.8191be6f5ad9e8b2
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
VirITWin32.Expiro.CV
CyrenW32/Expiro.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDG
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
KasperskyHEUR:Trojan.Win32.Expiro.gen
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
Ad-AwareWin32.Expiro.Gen.6
VIPREVirus.Win32.Expiro.dp (v)
TrendMicroVirus.Win32.EXPIRO.AD
SentinelOneStatic AI – Malicious PE
EmsisoftWin32.Expiro.Gen.6 (B)
IkarusVirus.Win32.Expiro
GDataWin32.Expiro.Gen.6
JiangminTrojan.PSW.Stealer.abj
AviraTR/Patched.Gen
Antiy-AVLTrojan/Generic.ASVirus.315
MicrosoftTrojan:Win32/Raccoon.EC!MTB
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacWin32.Expiro.Gen.6
MalwarebytesMalware.AI.1178432061
APEXMalicious
MAXmalware (ai score=80)
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.f5ad9e
PandaTrj/Genetic.gen

How to remove Malware.AI.1178432061?

Malware.AI.1178432061 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment