Malware

How to remove “Win32/Fusing.AX”?

Malware Removal

The Win32/Fusing.AX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Fusing.AX virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup

How to determine Win32/Fusing.AX?


File Info:

name: 528547577259F26CBFF0.mlw
path: /opt/CAPEv2/storage/binaries/e9ff388b5f90e6bd1c7e7ebe159d71285281a324b9fe1b960ec413f45a8cdc4d
crc32: 2F20F156
md5: 528547577259f26cbff034ae7d27129b
sha1: 06cb83323b77335d90df2b21ac158115d2801534
sha256: e9ff388b5f90e6bd1c7e7ebe159d71285281a324b9fe1b960ec413f45a8cdc4d
sha512: fe84823e70e483ab60ce962a56d2c416425565853aaf7d7b520e7ebe393400ae4d8c51bebc531535b41f9bf3a00cb97a7e109a388af0abfece4ab35b992957a7
ssdeep: 192:FohqgcJ3Bu7hOk/WQn9WBrI7CdtuboB4jhhf9AQF/L61oylSSy9SJAN0R:pg0Qno9QQso4jfTR61jF3W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13722D70B9E0411F3D46C03B008EBDF7AB16A9064135EAEB35398C6612DE57A3A8F714F
sha3_384: 8014ce7499c2017a276d1a92606b529586ad3adcb1283163675933fa8d98cc2630ac5907472d949925ddff52b1135281
ep_bytes: 558bec6aff6858164000681020400064
timestamp: 2009-10-19 10:36:31

Version Info:

0: [No Data]

Win32/Fusing.AX also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lCR2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.46061
MicroWorld-eScanGen:Heur.Conjar.9
FireEyeGeneric.mg.528547577259f26c
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 00191aeb1 )
K7GWTrojan ( 00191aeb1 )
Cybereasonmalicious.77259f
BitDefenderThetaAI:Packer.446CDC061F
CyrenW32/Zegost.AA.gen!Eldorado
ESET-NOD32a variant of Win32/Fusing.AX
TrendMicro-HouseCallTROJ_GEN.R03BC0PFI22
Paloaltogeneric.ml
ClamAVWin.Trojan.Magania-14323
KasperskyTrojan-GameThief.Win32.Magania.tzqw
BitDefenderGen:Heur.Conjar.9
NANO-AntivirusTrojan.Win32.Crypted.bcagig
AvastWin32:Dytka [Trj]
TencentMalware.Win32.Gencirc.114c34f9
Ad-AwareGen:Heur.Conjar.9
EmsisoftGen:Heur.Conjar.9 (B)
ComodoBackdoor.Win32.Agent.FLG@4of3sq
ZillyaTrojan.Magania.Win32.40238
TrendMicroTROJ_GEN.R03BC0PFI22
McAfee-GW-EditionBehavesLike.Win32.Infected.lt
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/Magania-O
IkarusTrojan-GameThief.Win32.Magania
JiangminTrojan/KillAV.cky
WebrootW32.Trojan.Gen
AviraTR/Spy.Gen
MAXmalware (ai score=80)
MicrosoftPWS:Win32/Zbot!ml
ViRobotBackdoor.Win32.A.Torr.116224.C
GDataGen:Heur.Conjar.9
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.PcClient.R6392
McAfeeArtemis!528547577259
TACHYONBackdoor/W32.Small.10752.Z
VBA32BScope.Trojan.SvcHorse.01643
APEXMalicious
RisingBackdoor.Farfli!1.64DB (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.9804515.susgen
FortinetW32/Redosdru.BED!tr
AVGWin32:Dytka [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Fusing.AX?

Win32/Fusing.AX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment