Malware

About “Malware.AI.159213362” infection

Malware Removal

The Malware.AI.159213362 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.159213362 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.159213362?


File Info:

name: 96586CA9D3BCEB010D6E.mlw
path: /opt/CAPEv2/storage/binaries/20f5c5cb7c4feeb495f4a759cdc6d749c802e2a24e7d72a9314dd6b896abbb35
crc32: 9AB45E3C
md5: 96586ca9d3bceb010d6e440f1546f2cf
sha1: e2ed000d0f6c81dd4f7e8f4e82f25560e6ad912a
sha256: 20f5c5cb7c4feeb495f4a759cdc6d749c802e2a24e7d72a9314dd6b896abbb35
sha512: a7c80b104456e988941187be0f6b92c3573237a0c83e02826978c66015fafedee5bbba6cd0c03b492d4e91e8c9db7c00c2265743aac7eff3dea189edc89d0c1a
ssdeep: 768:JzWT2rNYGKVqU4AgKZUk4JgVv0kWIcr7VLfeYKeQFzBpSXj/Ey0P:Jzsg1rjRKZUcVvD6qYKTsT0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148E2D04DEF0A9B48DB884B3861B71EB61A02F42E591E33533F49B8DEF5159636F49B00
sha3_384: f44afb1cf78ba8568f876113107fa0f7062faf43cffa82e23e422fb77987f125e3c06ae9359265652ba70320d48e5158
ep_bytes: 60be00c040008dbe0050ffff5783cdff
timestamp: 2003-10-27 16:29:57

Version Info:

0: [No Data]

Malware.AI.159213362 also known as:

BkavW32.Common.DCB34EB6
LionicTrojan.Win32.Presenoker.4!c
Elasticmalicious (moderate confidence)
SkyhighGenericRXEI-NO!16BDCEA86893
MalwarebytesMalware.AI.159213362
SangforTrojan.Win32.Agent.Vgol
Cybereasonmalicious.d0f6c8
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Malware-gen
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Crypt.XPACK.Gen
IkarusTrojan.Crypt
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare/Win32.Presenoker
Kingsoftmalware.kb.b.799
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!96586CA9D3BC
VBA32Adware.Presenoker
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06L723
RisingDropper.Generic!8.35E (C64:YzY0OsIDui4lvkNM)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)

How to remove Malware.AI.159213362?

Malware.AI.159213362 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment