Malware

What is “Malware.AI.58139796”?

Malware Removal

The Malware.AI.58139796 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.58139796 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Malware.AI.58139796?


File Info:

crc32: 24CE5956
md5: 59eaf6d9dc0efa46a9d14710288d8d49
name: 59EAF6D9DC0EFA46A9D14710288D8D49.mlw
sha1: c28196294e3b8fde6efe86fafab05c077ec0e760
sha256: 966471c37ae8bc1e7765e41b324af53e2684b0e5f7fc2bb566ecbc025e2e6234
sha512: 083ce81a62d495e097f8bf5595265b3e9246cee0cf044d64913af5e68802752c250ef0fbbe64b759566bde74ce574f886008a254a98c4322af15959ad6a17937
ssdeep: 6144:Go/Ld79PRcUbHQwzFa+XigCPycda4U88f6/ywAi9sLr/a:v/h9S+zFa2igCP12BrwtC3/a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009
InternalName: Setup
FileVersion: 1, 2, 0, 1
ProductName: Setup
ProductVersion: 1, 2, 0, 1
FileDescription: Setup
OriginalFilename: Setup
Translation: 0x0419 0x04b0

Malware.AI.58139796 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0001bc851 )
DrWebTrojan.BrowseBan.117
CynetMalicious (score: 100)
ALYacDropped:Trojan.Generic.2777342
CylanceUnsafe
ZillyaTrojan.Agent.Win32.72724
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/PornoBlocker.8d2ca6ff
K7GWTrojan ( 0001bc851 )
Cybereasonmalicious.9dc0ef
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.QJL
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.Inject-2975
KasperskyTrojan-Ransom.Win32.PornoBlocker.fs
BitDefenderDropped:Trojan.Generic.2777342
NANO-AntivirusTrojan.Win32.PornoBlocker.zvaqg
MicroWorld-eScanDropped:Trojan.Generic.2777342
TencentWin32.Trojan.Pornoblocker.Szly
Ad-AwareDropped:Trojan.Generic.2777342
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDropper.Agent.~JNN@1do8fa
BitDefenderThetaGen:NN.ZexaF.34684.Mu0@aebeY@ak
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.jt
FireEyeGeneric.mg.59eaf6d9dc0efa46
EmsisoftDropped:Trojan.Generic.2777342 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.acls
WebrootTrojan.Dropper
AviraTR/Crypt.XPACK.Gen5
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Occamy.C
GDataDropped:Trojan.Generic.2777342
AhnLab-V3Dropper/Win32.Agent.R371873
Acronissuspicious
McAfeeGenericR-HKZ!59EAF6D9DC0E
MAXmalware (ai score=100)
VBA32BScope.Trojan.Winlock
MalwarebytesMalware.AI.58139796
PandaGeneric Malware
RisingRansom.PornoBlocker!8.24E (CLOUD)
YandexTrojan.GenAsa!WTxzeadFHWc
IkarusTrojan-Dropper.Win32.Blocker
FortinetW32/Generic.AP.355410!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Malware.AI.58139796?

Malware.AI.58139796 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment