Malware

Malware.AI.1559606904 removal instruction

Malware Removal

The Malware.AI.1559606904 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1559606904 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Malware.AI.1559606904?


File Info:

name: 23B66D04ACDB284508A9.mlw
path: /opt/CAPEv2/storage/binaries/b55c59487cafcd40bfb4bf7af8052d540ab4c496e8a775440e756c9f075ab18e
crc32: B9CAE554
md5: 23b66d04acdb284508a9974497b38863
sha1: a9920420dfd1e9fc584443eb122cee3b4b1edb8e
sha256: b55c59487cafcd40bfb4bf7af8052d540ab4c496e8a775440e756c9f075ab18e
sha512: ec87204c0ebdf3f431fb71ddb1f94794920b4dcbd872d71ff62c016a32a7f1176280c9b8a5ccbbd0da62286a3c2c632faf3515b70f43866d10ea630d9084be65
ssdeep: 24576:37GO7dtrjrICw9XuXo7beSTdt5xbX02uvfTXfBxrj3d5E/jKQvVj4YpdjYY0td7j:qEtnrICSooGSTD5xbX022fjBxrj3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159559D12BE8EE432C563013205F9A70195B878B13E36C16BBFD84A3CDD747816A6F667
sha3_384: 9d8f200dfcd6450b8cce544218f7fb7947eb063558e3c4fbb6ed1c3a56344fb08b33ed65c196431c1dcb76954f1adab6
ep_bytes: 558bec6aff6800d15300683890530064
timestamp: 2018-03-15 13:16:01

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Neil Hodgson neilh@scintilla.org
FileDescription: SciTE Lite - a Scintilla based Text Editor modified by Jos for AutoIt3.
FileVersion: 3.5.4
InternalName: SciTE
LegalCopyright: Copyright 1998-2015 by Neil Hodgson
OriginalFilename: SciTE.EXE
ProductName: SciTE
ProductVersion: 3.5.4

Malware.AI.1559606904 also known as:

BkavW32.AIDetect.malware2
LionicVirus.Win32.Triusor.n!c
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Triusor.A
FireEyeGeneric.mg.23b66d04acdb2845
ALYacWin32.Triusor.A
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 004f12f91 )
Alibabavirus:Win32/InfectPE.ali2000007
K7GWTrojan ( 004f12f91 )
CyrenW32/Agent.EQI.gen!Eldorado
ESET-NOD32a variant of Win32/Resur.I
APEXMalicious
Paloaltogeneric.ml
BitDefenderWin32.Triusor.A
NANO-AntivirusVirus.Win32.Infector.eazaig
AvastWin32:Malware-gen
TencentWin32.Virus.Resur.Hrfi
Ad-AwareWin32.Triusor.A
SophosML/PE-A
ComodoTrojWare.Win32.Nimnul.A@5waoem
DrWebWin32.EquationKiller.1
TrendMicroVirus.Win32.RESUR.A
McAfee-GW-EditionBehavesLike.Win32.Triusor.th
Trapminemalicious.moderate.ml.score
EmsisoftWin32.Triusor.A (B)
GDataWin32.Trojan.PSE.1DUY8S4
AviraHEUR/AGEN.1240750
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeW32/Triusor.A
VBA32Virus.Win32.Triusor
MalwarebytesMalware.AI.1559606904
TrendMicro-HouseCallVirus.Win32.RESUR.A
RisingVirus.Resur!1.B42C (CLASSIC)
IkarusVirus.Win32.Resur
FortinetW32/Agent.FN
BitDefenderThetaAI:FileInfector.AD9B3E700F
AVGWin32:Malware-gen
Cybereasonmalicious.4acdb2

How to remove Malware.AI.1559606904?

Malware.AI.1559606904 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment