Malware

What is “Malware.AI.1120279545”?

Malware Removal

The Malware.AI.1120279545 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1120279545 virus can do?

  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1120279545?


File Info:

crc32: 23C3A7AA
md5: 05254134d5e2832550edd3f0658a698e
name: 05254134D5E2832550EDD3F0658A698E.mlw
sha1: e17d5b18a1ff0e2a4041c59355e3db13794b5aa9
sha256: 1dfa6c3dbfea0968a36e2f4e1751e53098224e07049135dacc48ce6e2a1e33b6
sha512: 4ded054bcca91da8f59768291bb835a7ccdf460b52b468c113d5b99c6627500b29994b1a5087b2ea75c1754e4488c219384a451080fb8539c3b4c6771290df42
ssdeep: 6144:NejAK3P4QL49yuzSy9D8WpaDmSEkBDK+AUN7i8w8JHh5xcbktw+h:sjAK3Loy+9DFpWZAM48JBHeMh
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x5f00x5fc3x4e0dx679c
CompanyName: x73a9x6e38x620f
FileVersion: 0.0.0.0
Comments: www.WanYX.com
FileDescription: x73a9x6e38x620f
Translation: 0x0804 0x04b0

Malware.AI.1120279545 also known as:

K7AntiVirusTrojan ( 004d0ccb1 )
LionicTrojan.Win32.StartPage.lIbO
Elasticmalicious (high confidence)
DrWebTrojan.Click1.53957
ClamAVWin.Trojan.Startpage-2521
McAfeeArtemis!05254134D5E2
CylanceUnsafe
ZillyaTrojan.StartPage.Win32.8389
AlibabaTrojan:Win32/StartPage.983bc13d
K7GWTrojan ( 004d0ccb1 )
Cybereasonmalicious.4d5e28
BaiduWin32.Trojan.StartPage.fa
CyrenAI/StartPage
SymantecTrojan.Gen.2
ESET-NOD32Win32/StartPage.AIW
APEXMalicious
AvastAutoIt:Agent-M [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.StartPage.dlw
BitDefenderTrojan.Generic.8745996
NANO-AntivirusTrojan.AutoIt.StartPage.dhpzl
MicroWorld-eScanTrojan.Generic.8745996
TencentWin32.Trojan.Startpage.Crd
SophosMal/Generic-S
ComodoMalware@#32caq9aiz03wz
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GGG21
McAfee-GW-EditionBehavesLike.Win32.Injector.fc
FireEyeTrojan.Generic.8745996
EmsisoftTrojan.Generic.8745996 (B)
JiangminTrojan.StartPage.dhz
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1105600
eGambitUnsafe.AI_Score_70%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Generic.8745996
AhnLab-V3Trojan/Win32.StartPage.R15102
VBA32IMWorm.Sohanad
MAXmalware (ai score=99)
MalwarebytesMalware.AI.1120279545
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0GGG21
RisingTrojan.Win32.Autoit.eqi (CLASSIC)
YandexTrojan.GenAsa!XGA/B1mg1DI
IkarusTrojan.Win32.StartPage
AVGAutoIt:Agent-M [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.1120279545?

Malware.AI.1120279545 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment