Malware

How to remove “Malware.AI.2586580012”?

Malware Removal

The Malware.AI.2586580012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2586580012 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Malware.AI.2586580012?


File Info:

name: 181C0F77AB225483676D.mlw
path: /opt/CAPEv2/storage/binaries/c1ffe0b168d6e6dfb2ad39361a045d3e4b4dfc32f2aca4c6797c612725bb0b87
crc32: 809F0486
md5: 181c0f77ab225483676d79846e14e7b2
sha1: 52a2e82863823ce17fcb245a662fbc3e3dd91f9a
sha256: c1ffe0b168d6e6dfb2ad39361a045d3e4b4dfc32f2aca4c6797c612725bb0b87
sha512: 49f7ddc99d2038f123c0403476967758e0559baa66a625b93760cbec7895273a0b4339975ce1b9784d3988d7fedd0ab57159d2a55c64a942ac47e5fe4ea1f31e
ssdeep: 768:abUsjmQsl9lUHwVNbgG8T/LCKR12/FMoOShZeGRh:abUdQoNU2NMcJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D53410326DD6EC6E6BD4771377247C4D3B9EE094132E60E2D89605C9CBD243BA927E2
sha3_384: 1824c0ccaa362b184f8a8b42a5d7585344abe06bf4dceb75482ec6a944d2ffeb354ee988c9d7dcedeae6a6c0d34bc6f3
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-09-28 17:32:31

Version Info:

Translation: 0x0000 0x04b0
Comments: Demonstration of RS232 interfacing with VB.Net
FileDescription: VB.Net Moasis GUI
FileVersion: 1.24.0.0
InternalName: Zeltiq - Main Env Chamber Shell 12P1.exe
LegalCopyright:
OriginalFilename: Zeltiq - Main Env Chamber Shell 12P1.exe
ProductVersion: 1.24.0.0
Assembly Version: 1.24.0.0

Malware.AI.2586580012 also known as:

LionicTrojan.MSIL.SpyGate.m!c
MicroWorld-eScanGen:Variant.Razy.718972
FireEyeGeneric.mg.181c0f77ab225483
ALYacGen:Variant.Razy.718972
CylanceUnsafe
ZillyaBackdoor.SpyGate.Win32.5213
SangforBackdoor.MSIL.SpyGate.afdu
AlibabaBackdoor:MSIL/SpyGate.c1d3b9f9
Cybereasonmalicious.7ab225
BitDefenderThetaGen:NN.ZemsilF.34294.dm0@aibCrZi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.JPFLNZT
TrendMicro-HouseCallTROJ_GEN.R002C0WH221
Paloaltogeneric.ml
KasperskyBackdoor.MSIL.SpyGate.afdu
BitDefenderGen:Variant.Razy.718972
NANO-AntivirusTrojan.Win32.SpyGate.ixsbzq
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Razy.718972
SophosMal/Generic-S
ComodoMalware@#5yfkpoiqf7sl
TrendMicroTROJ_GEN.R002C0WH221
McAfee-GW-EditionRDN/Generic PWS.y
EmsisoftGen:Variant.Razy.718972 (B)
APEXMalicious
AviraBDS/SpyGate.knmjw
Antiy-AVLTrojan/Generic.ASMalwS.28BF703
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Razy.718972
AhnLab-V3Trojan/Win32.SpyGate.R245816
McAfeeRDN/Generic PWS.y
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.2586580012
TencentMsil.Backdoor.Spygate.Dwjs
YandexBackdoor.SpyGate!1+5S6YA12tM
IkarusBackdoor.SpyGate
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/SpyGate.AFDU!tr.bdr
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Malware.AI.2586580012?

Malware.AI.2586580012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment