Worm

Worm.Macoute.S559150 removal guide

Malware Removal

The Worm.Macoute.S559150 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Macoute.S559150 virus can do?

  • Authenticode signature is invalid
  • CAPE detected the Macoute malware family
  • Anomalous binary characteristics

How to determine Worm.Macoute.S559150?


File Info:

name: 1B70CD9CF09B7420ADD3.mlw
path: /opt/CAPEv2/storage/binaries/357d0713d1c365808662796db420227a01171bab6a6622be778a114ef7472841
crc32: 302B59A9
md5: 1b70cd9cf09b7420add374541a32b3d3
sha1: 431af67d100e4c9036612d9648ad16c918900a05
sha256: 357d0713d1c365808662796db420227a01171bab6a6622be778a114ef7472841
sha512: 47549a4815db518cbb313cc43e87db004b49e8630a7426c697866f20fb4355a81ded4a6990e1d191563b6a8c331a0c539fa4bcc44dd90cb9f3f504891a955a19
ssdeep: 6144:CafsiuvAQ+tTm6cyERSiytj71cLE4jKS6vC6t:/CvAQ+q6ctRt636LfjOD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T187A4AF82EBD340F1D8970F72546BA77F9B324A0E502CDD5AD3942E56AC33323A92E754
sha3_384: abc57ab77cf16baa2ac87d717868ba72b0caef140a0f91779f9f41fee5704ab364c5492042eefa338132fb7b554a71b8
ep_bytes: 586a01e8ec3f0100585ac35557565350
timestamp: 1995-02-26 23:24:20

Version Info:

0: [No Data]

Worm.Macoute.S559150 also known as:

LionicTrojan.Win32.Agentb.m9mM
Elasticmalicious (high confidence)
FireEyeGeneric.mg.1b70cd9cf09b7420
CAT-QuickHealWorm.Macoute.S559150
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/A-98aec620!Eldorado
SymantecML.Attribute.HighConfidence
BaiduWin32.Worm.Agent.fl
TrendMicro-HouseCallPE_VIRUX.S-1
Paloaltogeneric.ml
ClamAVWin.Malware.Zusy-9889629-0
KasperskyVirus.Win32.Virut.ce
SUPERAntiSpywareWorm.PasswordStealer/Variant
AvastWin32:Dropper-GUP [Drp]
TencentTrojan.Win32.Keylogger.aa
ComodoHeur.Corrupt.PE@1z141z3
TrendMicroPE_VIRUX.S-1
McAfee-GW-EditionBehavesLike.Win32.Backdoor.gm
SophosMal/Generic-S
IkarusTrojan.Win32.Scar
GDataWin32.Trojan.PSE.10XMVYJ
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
APEXMalicious
MicrosoftWorm:Win32/Macoute.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R160138
Acronissuspicious
MalwarebytesTrojan.PasswordStealer
RisingWorm.Macoute!1.A746 (CLASSIC)
YandexTrojan.GenAsa!53PMqSgQMYw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/CoinMiner.CE
AVGWin32:Dropper-GUP [Drp]
Cybereasonmalicious.d100e4
PandaW32/Sality.AO

How to remove Worm.Macoute.S559150?

Worm.Macoute.S559150 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment