Malware

About “Malware.AI.977159730” infection

Malware Removal

The Malware.AI.977159730 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.977159730 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.977159730?


File Info:

name: 5C68BFF3131FA1CB3A72.mlw
path: /opt/CAPEv2/storage/binaries/a6bf61f9e230f2fe039f5d97aa3a2e1911c7f3467d8f81825f04024c0eb5d7a7
crc32: 6A6470E7
md5: 5c68bff3131fa1cb3a7274154405d982
sha1: 7499bd35f3a44323f971022e30d472f42a5761ab
sha256: a6bf61f9e230f2fe039f5d97aa3a2e1911c7f3467d8f81825f04024c0eb5d7a7
sha512: 339c4a34ada1a3a4967b78295293f49ce9d6318aec138097cb5f9574819b55b070d8a92ceb5de30782440e02074379bcf62a837f2e312bdada8278d3072b9a25
ssdeep: 12288:4YgFKpUEqkCPsBNkqQ5Cz9HJqnu/J1dMEoEzTpTx:J6EqkCEBNkqQ5Cv+u/DdMEFTpTx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152F4AE02F1A580B5DA0A0D702CADEB39AE649FD99F251AC7A3E4FE1D15335F2D437218
sha3_384: 4c22956afdc845af6c66592c0709346387b7ab3eb8f752184dac29f51c6415e81bb5e4aa27005516fab487a0686f3d16
ep_bytes: 558bec6aff68385145006874d4420064
timestamp: 2011-02-03 15:11:52

Version Info:

0: [No Data]

Malware.AI.977159730 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Strictor.4!c
DrWebTrojan.Muldrop8.41845
MicroWorld-eScanGen:Variant.Zusy.390939
FireEyeGeneric.mg.5c68bff3131fa1cb
ALYacGen:Variant.Zusy.390939
Cylanceunsafe
VIPREGen:Variant.Zusy.390939
SangforSuspicious.Win32.Save.ins
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderGen:Variant.Zusy.390939
NANO-AntivirusTrojan.Win32.Ursu.fiquag
AvastFileRepMalware [Trj]
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Sality.bh
EmsisoftGen:Variant.Zusy.390939 (B)
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Zusy.390939
XcitiumTrojWare.Win32.Spy.Zbot.BPOE@4vq0n5
ArcabitTrojan.Zusy.D5F71B
MicrosoftTrojan:Win32/Zpevdo.B
GoogleDetected
McAfeeArtemis!5C68BFF3131F
VBA32Trojan.MulDrop
MalwarebytesMalware.AI.977159730
TrendMicro-HouseCallTROJ_GEN.R002H09GT23
RisingTrojan.Generic@AI.100 (RDML:DphRCnAWhqEVaKoMFUIx/g)
YandexTrojan.Muldrop!C7XswWuE2bs
MaxSecureTrojan.Malware.118982065.susgen
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.977159730?

Malware.AI.977159730 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment