Malware

What is “Malware.AI.1056805245”?

Malware Removal

The Malware.AI.1056805245 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1056805245 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1056805245?


File Info:

crc32: 2288FCAF
md5: aa414f185a7eb548d0ff7e39bed322f3
name: AA414F185A7EB548D0FF7E39BED322F3.mlw
sha1: 7e1ca324922cf21093d9ad7380583fc25bb8189b
sha256: 309ada9bb589ec95204d7cd03a9c803a0cfd2edb01f4fba3c40d09be35e357f2
sha512: ef035faa7f746d102ea18b7831fa62d02f812d1454eb46fd7588c452e2749cabbcadd4c33edec194224cb1137e7b1d6e7f2d33717dda33bdce5c55bf2e65de70
ssdeep: 6144:pxWZ2Yr/RMzSdhgDNILAiyW9YiqGtrqH0T52n0zmhLWjIrQtVYCYVIJInhynR6W:bW3r/gmy5Ab3vsH0d20+YIrgYpnhynX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: dfgdfg.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: dfgdfgdfg.exe
Translation: 0x040c 0x04b0

Malware.AI.1056805245 also known as:

K7AntiVirusTrojan ( 0055e3991 )
LionicTrojan.Win32.Locky.tq0G
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
CynetMalicious (score: 100)
ALYacTrojan.Ransom.AWG
CylanceUnsafe
ZillyaTrojan.Locky.Win32.254
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.85a7eb
ESET-NOD32a variant of Win32/Injector.CYUZ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Locky.zp
BitDefenderTrojan.Ransom.AWG
NANO-AntivirusTrojan.Win32.Encoder.ecnnsn
MicroWorld-eScanTrojan.Ransom.AWG
TencentMalware.Win32.Gencirc.10c09d9d
Ad-AwareTrojan.Ransom.AWG
ComodoMalware@#1vncxa4fprnh1
BitDefenderThetaGen:NN.ZexaF.34142.By0@aeLjFWdm
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_HPISDA.SM
FireEyeGeneric.mg.aa414f185a7eb548
EmsisoftTrojan.Ransom.AWG (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Locky.wo
AviraHEUR/AGEN.1103329
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.18E6CC5
MicrosoftTrojan:Win32/Tiggre!rfn
GDataTrojan.Ransom.AWG
TACHYONRansom/W32.Locky.455680
AhnLab-V3Trojan/Win32.Locky.C2301551
Acronissuspicious
McAfeePacked-HB!AA414F185A7E
MAXmalware (ai score=100)
VBA32Hoax.Locky
MalwarebytesMalware.AI.1056805245
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_HPISDA.SM
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!7h5u2wqJTWY
IkarusTrojan.Win32.Crypt
FortinetW32/Bebloh.P!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Malware.AI.1056805245?

Malware.AI.1056805245 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment