File verdict·Decided by the MT AI Engine
Our call

Safe

A small 64-bit Windows driver (viruz.sys) with an invalid signature, flagged malicious by only 2 out of 76 engines including Bkav and McAfee, while top engines like BitDefender and Kaspersky see nothing wrong.

Trust score30High risk
MT AI confidence · 25%
viruz.sys
6.7 KB
ce5b7aad9b51a3df9b462f6333a7
Antivirus engines
2 of 76 flagged
Code signing
Unsigned
Age
First seen 1y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

25%Confidence
Exploratory
Reasoning

The file presents as a 6904-byte Win32 executable disguised as a .sys driver, first seen in early 2025, with PE tags showing it's 64-bit, has an overlay, and an invalid signature. Our antivirus network ran 76 scans: just 2 malicious hits from Bkav's AI generic detection and McAfee's hash-based alert, while tier-1 engines like BitDefender, Kaspersky, ESET, Avast, and others report it undetected. This low detection count (2/76) points to a likely false positive, especially with no consensus on a specific threat family. If run, it might attempt generic malicious behavior due to the detections, but the disagreement suggests it's probably safe. Quarantine or delete it to be cautious.

Points in its favour
  • 70 out of 76 engines report undetected, including all tier-1 like BitDefender, Kaspersky, ESET.
  • No popular threat labels or named families from our analysis.
  • No suspicious or PUA detections.
  • Small file size consistent with some legit drivers.
Points against
  • Invalid digital signature on a .sys driver file, which drivers shouldn't have.
  • Suspicious name 'viruz.sys' evoking 'virus'.
  • Bkav detects it as W64.AIDetectMalware (generic AI-based malware alert).
  • McAfeeD flags it via hash (ti!CE5B7AAD9B51), indicating behavioral suspicion.
  • PE overlay data, often used to hide malicious payloads.
  • Recently first seen (2025), low reputation.
What to do

Immediately delete or quarantine viruz.sys and run a full system scan with your antivirus. Avoid running unknown .sys files, as they can load at boot with high privileges.

Sources disagree

2 contradictions resolved by the scoring engine

Only low-trust / heuristic engines flagged this file
2 engines from the heuristic / generic-AI set flagged it. No tier-1 engine agreed.
Verdict treated these as likely false positives.
MT AI Engine read "suspicious", displayed verdict is "safe"
A ground-truth gate (admin override, MalwareBazaar, empty-file) or the low-confidence display rule shifted the final call.
Displayed verdict tracks the harder evidence.
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

2 detections across 76 engines

2 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
2flag
Heuristic / generic-AI engines (high FP rate)
Our scoring rated this file safe — detections shown below are weighted as likely false positives.
Bkav
malicious
W64.AIDetectMalware
McAfeeD
malicious
ti!CE5B7AAD9B51
Hash ce5b7aad9b51… cross-referenced against 76 AV engines via our AV network.
File identity

Forensic fingerprint

File biography
First seen (VT)
1/23/2025, 4:54:47 PM
First seen (MalwareBazaar)
Last analysis (VT)
4/4/2026, 5:55:10 AM
Scanned here
4/20/2026, 2:30:10 PM
File name
viruz.sys
Size
6.7 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
ce5b7aad9b51a3df9bbaff5526c1addcb844ed7aeb1fca368d7b41462f6333a7
MD5
b69d358dd6971f7969942576e85cdc7f
SHA-1
0b1dd0b32b8056302d7151182e06788cefa89978
PE imphash
153145b9975a097e9b9f0bc04730ffd7
First seen (VT)
1/23/2025, 4:54:47 PM
Last analysis (VT)
4/4/2026, 5:55:10 AM
First scan (MalwareTips)
4/20/2026, 6:37:36 AM
Last scan (MalwareTips)
4/20/2026, 2:30:10 PM
Behavior tags
64bitspeexeoverlaysignednativeinvalid-signature
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.