Malware

What is “Malware.AI.602061615”?

Malware Removal

The Malware.AI.602061615 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.602061615 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.602061615?


File Info:

name: 7B84D9EEAF0CE5F1973B.mlw
path: /opt/CAPEv2/storage/binaries/decb60531b198aba1c3807be9e696a832a362b750e2372d30230eeafda4388ba
crc32: 45123F77
md5: 7b84d9eeaf0ce5f1973b92b4640cbbe0
sha1: 7178ff4c35c7920f0ff230d6eda5d8701c3ee2fc
sha256: decb60531b198aba1c3807be9e696a832a362b750e2372d30230eeafda4388ba
sha512: 7da5cbe73b4ff717f227118a645f635f4f139919e825be181bf5c93b82a6c195fe0b4e40fd47bbc2e1dd4925ce0ec1f42495fc59866e8baec461df3ea73b4959
ssdeep: 6144:krZokeLUjD5hkk/YMgptN7oljKy8xvhNV/epOykI012goqa3Zsa2U3282nD+oWAS:q+UjD5hk/MgrmBKy8x30OykVP0h2wCDm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A54E19177D4ABE1EEB5003406BB1D7B623BAF1133819BCB77A1B675EF36051C12A680
sha3_384: ad527c7d812bc5db548d9c5782af23583d0363513e1c777dac8b2e0174fd718abb257efe35661bc607d3fc9c1dc4ad58
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2016-12-12 01:38:53

Version Info:

CompanyName: Mozilla Corporation
FileDescription: Mozilla Maintenance Service Installer
FileVersion: 73.0.1
LegalCopyright: Mozilla Corporation
LegalTrademarks: Firefox is a Trademark of The Mozilla Foundation.
OriginalFilename: maintenanceservice_installer.exe
ProductName: Firefox
ProductVersion: 73.0.1
Translation: 0x0409 0x04b0

Malware.AI.602061615 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Doina.63293
ALYacGen:Variant.Doina.63293
MalwarebytesMalware.AI.602061615
VIPREGen:Variant.Doina.63293
BitDefenderGen:Variant.Doina.63293
ArcabitTrojan.Doina.DF73D
CyrenW32/S-25822568!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 99)
APEXMalicious
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Generic@AI.100 (RDML:NRRgliRQw06vHFgi36tQVg)
F-SecureHeuristic.HEUR/AGEN.1363959
ZillyaBackdoor.Convagent.Win32.5739
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.moderate.ml.score
FireEyeGen:Variant.Doina.63293
IkarusTrojan.Win32.Patched
AviraHEUR/AGEN.1363959
Antiy-AVLTrojan/Script.Phonzy
Kingsoftmalware.kb.a.975
XcitiumMalCrypt.Indus!@1qrzi1
MicrosoftTrojan:Win32/Doina.RPX!MTB
GDataGen:Variant.Doina.63293
GoogleDetected
AhnLab-V3Malware/Win.Generic.R604244
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Convagent
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Adware_AGen
AVGWin32:Patched-AWW [Trj]
Cybereasonmalicious.c35c79
AvastWin32:Patched-AWW [Trj]

How to remove Malware.AI.602061615?

Malware.AI.602061615 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment