Malware

About “Malware.AI.678557530” infection

Malware Removal

The Malware.AI.678557530 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.678557530 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.678557530?


File Info:

name: 4DA568F6CCEB2A6CC70E.mlw
path: /opt/CAPEv2/storage/binaries/499cfa2394ae3a92a2d4d57279dc3a234cefae8eadc3ec45eb0d6a6006598ba0
crc32: C7F50A67
md5: 4da568f6cceb2a6cc70ef563b0d65d15
sha1: be772a0a3b3ca3ea4ed1212beaf9234287bafd11
sha256: 499cfa2394ae3a92a2d4d57279dc3a234cefae8eadc3ec45eb0d6a6006598ba0
sha512: d41fbc4fb0b646f52c80ce6332d993c25c0ec9ab94a5caa2a5b5b0344b53a2075c7f230eaa1cd8a83aab9a73dc52620dacf0e0979a97aad44657e293282526ec
ssdeep: 12288:RWpUhPQFrUo+03/DipGUFNn18bP3nCeVRu1IgekV+:RWvWL0vbm18OUMIgekI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114255A7366F6A810E46E0DB01461BA3092367E112A6F4CD7F94DB66F98337C2356D32B
sha3_384: 840425d8780660be0a2005635b992b36ceab0c57ecebb848323ae34110e735ccb91be253bf2800e8a492c65645156691
ep_bytes: e8a6020000e935fdffffccff25ac2040
timestamp: 2006-10-23 07:29:32

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Reader 8.0
FileVersion: 8.0.0.2006102200
LegalCopyright: Copyright 1984-2006 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Reader
ProductVersion: 8.0.0.2006102200
OriginalFilename: AcroRd32Info.exe
Translation: 0x0409 0x04e4

Malware.AI.678557530 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
MalwarebytesMalware.AI.678557530
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/A-bce2c6f5!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Ipamor-9935088-0
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
JiangminPacked.Krap.gvwy
GDataWin32.Trojan.PSE.UNPBF5
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.0F9C!tr
Cybereasonmalicious.a3b3ca

How to remove Malware.AI.678557530?

Malware.AI.678557530 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment