Malware

Should I remove “Malware.AI.1424951046”?

Malware Removal

The Malware.AI.1424951046 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1424951046 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.1424951046?


File Info:

name: EBAD9806D0844837D891.mlw
path: /opt/CAPEv2/storage/binaries/85337ab4d7d91d4492cc9a9d32f4b688dd7208b60af632ac2a846aafa81df3fc
crc32: 07A080CB
md5: ebad9806d0844837d891e153e08e7aca
sha1: bf05a5e1c2c4a60d335f7ed739695ac53382aa5e
sha256: 85337ab4d7d91d4492cc9a9d32f4b688dd7208b60af632ac2a846aafa81df3fc
sha512: b8a36d0cf2f5a2fee4b7d4b4743f32c02360eab083000d882d30f6061a83bb74d5a50b088094474efa03424836b3b2ec7f653ab940745434d1ad34f6b00dc2fb
ssdeep: 6144:lEM0e3y70cNjOcm9BBm5SqES82Z6L2Bh3CsRO0XmVD+7IoSR:70w4hOhBmzES8szyHCEoSR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B741A5E7C16E446C32A86F4989F0DF9153268A7EA7D5B2FD97E781AF0182B1D830313
sha3_384: 4faeff01a03bf7eaf72e29e5edc5b290ff36b8027819eced803591c3ebd68893e6857e1bb36c81b575087f4550a380b9
ep_bytes: e8e2fbfdffe999feffff000000000000
timestamp: 2011-06-29 19:57:54

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Экранная клавиатура
FileVersion: 5.1.2600.5512 (xpsp.080413-2105)
InternalName: osk
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: osk.exe
ProductName: Операционная система Microsoft® Windows®
ProductVersion: 5.1.2600.5512
Translation: 0x0419 0x04b0

Malware.AI.1424951046 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Kazy.54575
FireEyeGeneric.mg.ebad9806d0844837
ALYacGen:Variant.Kazy.54575
CylanceUnsafe
VIPRETrojan.Win32.Reveto.D (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/EncPk.2286b5d0
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.6d0844
VirITTrojan.Win32.Generic.AFBL
CyrenW32/Zbot.DP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-685564
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.54575
NANO-AntivirusTrojan.Win32.ZBot.vxpsv
SUPERAntiSpywareTrojan.Agent/Generic
AvastWin32:Crypto-AV [Trj]
TencentMalware.Win32.Gencirc.10b66d7f
Ad-AwareGen:Variant.Kazy.54575
EmsisoftGen:Variant.Kazy.54575 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Siggen8.15737
ZillyaDropper.Injector.Win32.14865
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosMal/Generic-R + Mal/EncPk-ABFO
IkarusTrojan-Ransom.Foreign
GDataGen:Variant.Kazy.54575
JiangminTrojan.Generic.dxcee
WebrootW32.Malware.Gen
AviraTR/Spy.Zbot.yhmf
MAXmalware (ai score=99)
Antiy-AVLTrojan[Dropper]/Win32.Injector
MicrosoftTrojan:Win32/Occamy.C85
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.Injector.R20133
Acronissuspicious
McAfeeGenericRXGU-GU!EBAD9806D084
VBA32BScope.Trojan.Dynamer
MalwarebytesMalware.AI.1424951046
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!XR5pXvvqcO8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Kryptik.ABC!tr
BitDefenderThetaGen:NN.ZexaF.34212.vm1@a891h9oi
AVGWin32:Crypto-AV [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1424951046?

Malware.AI.1424951046 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment