Malware

Malware.AI.1178653070 malicious file

Malware Removal

The Malware.AI.1178653070 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1178653070 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1178653070?


File Info:

name: 024FD23203023C3660C9.mlw
path: /opt/CAPEv2/storage/binaries/aca169b755765eb282faebf6d2ca129eca35754cf5c97e89993214053ad78dc7
crc32: 16166377
md5: 024fd23203023c3660c9af942f4cfe1e
sha1: 264985e434fca09de4862f8c1d32507bdfd0a803
sha256: aca169b755765eb282faebf6d2ca129eca35754cf5c97e89993214053ad78dc7
sha512: 9292bcc521f535eede1fc8c94ed2fb20bd96459def00c38945edca100126c2b034cea1edbe8e7b3062242b277a02b2da1176e2a7cb63b536b8ac33060968f328
ssdeep: 12288:kWuMZ7SMzBxa4F6n6deTfUlvo2xdcjbpP4n0K0qtyGkmolhPpjT:6MZ7Dz+04yewlvo2x6jlgnZAltpjT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198C40202DB8D14DEC07D8933C5F5B824708D2CB90AA617593630BF877BB96D14AA6CEC
sha3_384: a34487618d39381713786655cbb60cf6b4296f01b99a97a0a6c1b5b156e79e303a371c341e4659d41d3255db7b3d0c02
ep_bytes: 60be00704d008dbe00a0f2ff5783cdff
timestamp: 2021-08-19 14:43:51

Version Info:

0: [No Data]

Malware.AI.1178653070 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zusy.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.406653
FireEyeGeneric.mg.024fd23203023c36
ALYacGen:Variant.Zusy.406653
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Protect.379e1fc0
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.434fca
BitDefenderThetaGen:NN.ZexaF.36722.KmGfayqQQpgb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.406653
NANO-AntivirusTrojan.Win32.Strictor.jpefsh
AvastWin32:MiscX-gen [PUP]
EmsisoftGen:Variant.Zusy.406653 (B)
VIPREGen:Variant.Zusy.406653
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
GDataWin32.Trojan.PSE.4AIOBO
JiangminTrojan/Genome.bfxh
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Zusy.D6347D
MicrosoftTrojan:Win32/Wacatac.A!ml
GoogleDetected
AhnLab-V3Malware/Gen.Generic.C4034250
McAfeeRDN/Real Protect-LS
MAXmalware (ai score=81)
MalwarebytesMalware.AI.1178653070
TrendMicro-HouseCallTROJ_GEN.R002H0CI323
RisingTrojan.Generic@AI.99 (RDML:UVxy6lHhtQn+wfRXnzLSuA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:MiscX-gen [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.1178653070?

Malware.AI.1178653070 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment