Malware

Malware.AI.1613028326 removal guide

Malware Removal

The Malware.AI.1613028326 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1613028326 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1613028326?


File Info:

name: A61AA8D957FD299A3B29.mlw
path: /opt/CAPEv2/storage/binaries/9e52da447df93b18c94c2e169ab27921c637d1ccd76eb95508e2d36136f54001
crc32: B20622F3
md5: a61aa8d957fd299a3b293c81f6ba3942
sha1: 1ba4cba8efdfa559dcc9796e6a394c7b8b21e7b5
sha256: 9e52da447df93b18c94c2e169ab27921c637d1ccd76eb95508e2d36136f54001
sha512: 397fd35238cc29972dc558aa2a03ba167bf14f8b97aa39e5e687b3dfce40834ea10b1836c17e7e78f89c1bd9d9ca1d6aa6cf59e4e268a4b48a72eec6c23639c0
ssdeep: 24576:P8gY+tQCh1hYLKhvyCFw2BKLfRlZHWXwom8eYyCmWuQ5p3h3X3:P8gY+tQCh1hYLUPBEfYAomGyk
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T145B509039B8B0E75DDC27BB4A1CB633A9734EE30CA269B7FF608C53559532C5681A742
sha3_384: ca9c9542c925cf1d92c627744e2aeca74c1ae46ff6fecf2a827ab159511f7f45c6721954bb08aa1d1fa555a3bddd2009
ep_bytes: 83ec1cc7042401000000ff15e8625100
timestamp: 2022-06-04 11:47:21

Version Info:

0: [No Data]

Malware.AI.1613028326 also known as:

McAfeeGenericRXTE-ZT!A61AA8D957FD
CylanceUnsafe
BitDefenderGen:Variant.Babar.59485
CyrenW32/Kryptik.GTB.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HPTA
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Babar.59485
Ad-AwareGen:Variant.Babar.59485
EmsisoftGen:Variant.Babar.59485 (B)
FireEyeGen:Variant.Babar.59485
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Babar.59485
MAXmalware (ai score=88)
ArcabitTrojan.Babar.DE85D
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ALYacGen:Variant.Babar.59485
MalwarebytesMalware.AI.1613028326
BitDefenderThetaGen:NN.ZexaF.34712.p!Z@a4P5qsf

How to remove Malware.AI.1613028326?

Malware.AI.1613028326 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment