Malware

Malware.AI.2159405886 removal

Malware Removal

The Malware.AI.2159405886 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2159405886 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.2159405886?


File Info:

name: E525C19AB2A182DD82B9.mlw
path: /opt/CAPEv2/storage/binaries/92e7c74e0cc6e7f6289eba4e395c399478409e9448a6f2cc5cdf5d7ea566c2cf
crc32: 6C35BC6F
md5: e525c19ab2a182dd82b9791ffd2ae20c
sha1: 4d284a241ec7ad333926e9ac1d6f2812da3ab239
sha256: 92e7c74e0cc6e7f6289eba4e395c399478409e9448a6f2cc5cdf5d7ea566c2cf
sha512: f3b0794563c223e88e7e55c8a890143e06ef58015158f0612c88908c5a9f2a91e7af83e97b76cbae913593900be180e5d52c39ee0dbaefbe7edc027d306c5edc
ssdeep: 768:/VF3CCgNINHcNhwAGLx0v7fHTQzRssMmP8tmP8yQzRss3:dFJVcNhwAlPQzRssMm0tm0yQzRss
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC6384221B9DBDD9E19E2A75193973105AA2E85493E04BCF4F9025EE6C320D3FC3275B
sha3_384: 37aab4a92105f81201888e6986c69f7480c1ddd416e364432aa37f521d3b8675a596e600fa9e746e74a2f2ad999b1f09
ep_bytes: 8b6845408b8bff1530ff8bff68cc6a30
timestamp: 2071-10-08 19:21:25

Version Info:

0: [No Data]

Malware.AI.2159405886 also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Upatre.100
MicroWorld-eScanGen:Variant.Mikey.30054
FireEyeGeneric.mg.e525c19ab2a182dd
CAT-QuickHealTrojanpwszbot.Gsb
ALYacGen:Variant.Mikey.30054
MalwarebytesMalware.AI.2159405886
ZillyaDownloader.Agent.Win32.508706
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36164.eyY@aiDJf!j
CyrenW32/Bredolab.L.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Upatre-6740969-0
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
BitDefenderGen:Variant.Mikey.30054
NANO-AntivirusTrojan.Win32.Upatre.dggcix
AvastWin32:Agent-AULS [Trj]
TencentMalware.Win32.Gencirc.10bea5f5
EmsisoftGen:Variant.Mikey.30054 (B)
F-SecureTrojan.TR/Redcap.cafaj
BaiduWin32.Trojan-Downloader.Waski.a
VIPREGen:Variant.Mikey.30054
TrendMicroTROJ_GEN.R03BC0DDQ23
McAfee-GW-EditionBehavesLike.Win32.Generic.kz
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Mikey.30054
GoogleDetected
AviraTR/Redcap.cafaj
MAXmalware (ai score=87)
Antiy-AVLTrojan[Downloader]/Win32.Agent
XcitiumTrojWare.Win32.TrojanDownloader.Waski.EB@5j320p
ArcabitTrojan.Mikey.D7566
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PWSZbot.R569250
Acronissuspicious
McAfeeArtemis!E525C19AB2A1
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DDQ23
RisingDownloader.Agent!8.B23 (TFE:2:R5mULGmjPKH)
IkarusTrojan.Win32.PWSZbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Agent-AULS [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.2159405886?

Malware.AI.2159405886 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment