Malware

Malware.AI.2559814620 removal

Malware Removal

The Malware.AI.2559814620 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2559814620 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2559814620?


File Info:

name: 57F1D8A9D6721F92C884.mlw
path: /opt/CAPEv2/storage/binaries/bb6781f5af8afd5576c33319de00c9c2fee811d75bfc1ff83e6f192c8442fa3a
crc32: F8775A68
md5: 57f1d8a9d6721f92c88460368921412f
sha1: adc8321cb06af6888c05bdfe53cba5a252a55ca9
sha256: bb6781f5af8afd5576c33319de00c9c2fee811d75bfc1ff83e6f192c8442fa3a
sha512: 34f9fe08b2aeeab135d5b15135609080922f880fc84f1e8cf7153c848eeb60ebcf9faf190d72b6e9a52f7f7fa4f79e6b64e41b959b7818c65432cf7f324423ae
ssdeep: 768:NkYTL0bL6eLz7vydjFFw0rqEIn5CHV7M5EHdMtSLWgrZD228kAnc+m:uqA6ynvyfFwxBn5czHmIWEZaxDm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C330289E3F824BBE0265AB7595AB730077C2475F361CB1B5D4FEAF1243406DE918608
sha3_384: 40608511b9b02c22299c7c21d3d1b73429a3be432282e46657db00e3d5077ba29872221a67fbbf9d3a850f80131816f4
timestamp: 2008-10-18 05:44:13

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: Generic Host Process for Win32 Services
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: svchost.exe
LegalCopyright: ? Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: svchost.exe
PrivateBuild:
ProductName: Microsoft? Windows? Operating System
ProductVersion: 5.1.2600.2180
SpecialBuild:
Translation: 0x0804 0x04b0

Malware.AI.2559814620 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
SkyhighBehavesLike.Win32.Generic.qc
McAfeegeneric!bg.evs
MalwarebytesMalware.AI.2559814620
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0059886f1 )
K7GWUnwanted-Program ( 0059886f1 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITBackdoor.Win32.PcClient.LB
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:RootkitX-gen [Rtk]
RisingMalware.Undefined!8.C (TFE:5:Wg5O0CiDUQM)
F-SecureTrojan.TR/FakeSysdef.azxce
FireEyeGeneric.mg.57f1d8a9d6721f92
SophosGeneric ML PUA (PUA)
IkarusTrojan.Backdoor.PcClient
JiangminBackdoor/Agent.brhr
AviraTR/FakeSysdef.azxce
Kingsoftmalware.kb.b.987
MicrosoftTrojan:Script/Phonzy.B!ml
GoogleDetected
AhnLab-V3Backdoor/Win32.Nbdd.R2022
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
AVGWin32:RootkitX-gen [Rtk]
Cybereasonmalicious.cb06af
DeepInstinctMALICIOUS

How to remove Malware.AI.2559814620?

Malware.AI.2559814620 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment