Malware

What is “suspected of Corrupted.Win32File.EPIIT”?

Malware Removal

The suspected of Corrupted.Win32File.EPIIT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What suspected of Corrupted.Win32File.EPIIT virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine suspected of Corrupted.Win32File.EPIIT?


File Info:

name: AB23CC45EFB59B66A827.mlw
path: /opt/CAPEv2/storage/binaries/64be48a5ae6480f84a2ed0d3e95deda1588d01f0a8b65a1f3c7b7af3c483270c
crc32: 98BDF310
md5: ab23cc45efb59b66a82727a3bf563a67
sha1: 42643067d87cf59c1f1e7dd735874b40a8a4a8a0
sha256: 64be48a5ae6480f84a2ed0d3e95deda1588d01f0a8b65a1f3c7b7af3c483270c
sha512: bc50ed9d79493694e4e84b4f52e513bf7b899222ee5dd74d58bf46323c835ede1f6c960cc48722a42b53a1fb5319b2d3e70731112a1d13ad3dea46ef9b239b68
ssdeep: 6144:0qoD0Bm2qWKSDGET3hFN9iK9XzGrL80Gd0WhSY7/qyB13+SaBVaBX:foHBtGnT3hb9iAzGrLxWhSo/q0pAM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168647C00AA90C0F5F5FA12F449769378B92D7EB0972550DBA2E42AEE57346E0EC3171F
sha3_384: 844b115e38b1ec9337cdbb1fa64e87ee363598d35d7704fcd2e2f21e8d9cab22431d92ccf75e11f440f321acfbb6c820
ep_bytes: 8d80b5990000ff200000000000000000
timestamp: 2021-12-29 13:17:07

Version Info:

Translations: 0x0489 0x00aa

suspected of Corrupted.Win32File.EPIIT also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.91386
ClamAVWin.Packed.Pwsx-9965190-0
CAT-QuickHealTrojan.AgentIH.S28527429
ALYacTrojan.GenericKDZ.91386
CylanceUnsafe
VIPRETrojan.GenericKDZ.91386
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0059771e1 )
K7AntiVirusTrojan ( 0059771e1 )
CyrenW32/Kryptik.HKK.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HQQH
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderTrojan.GenericKDZ.91386
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKDZ.91386
EmsisoftTrojan.GenericKDZ.91386 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.DownLoader45.13232
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ab23cc45efb59b66
SophosML/PE-A
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLGrayWare/Win32.Kryptik.hqno
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D164FA
SUPERAntiSpywareBackdoor.Bot/Variant
GDataWin32.Trojan.PSE.1LTE0V1
GoogleDetected
AhnLab-V3Packed/Win.GEE.R512606
McAfeeGenericRXAA-AA!AB23CC45EFB5
MAXmalware (ai score=80)
VBA32suspected of Corrupted.Win32File.EPIIT
MalwarebytesTrojan.MalPack.GS
RisingBackdoor.Androm!8.113 (TFE:5:Xsvb5B2YuUC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.7d87cf
PandaTrj/GdSda.A

How to remove suspected of Corrupted.Win32File.EPIIT?

suspected of Corrupted.Win32File.EPIIT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment