Malware

About “Malware.AI.1141245565” infection

Malware Removal

The Malware.AI.1141245565 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1141245565 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1141245565?


File Info:

crc32: 05239392
md5: f6b668d80e37f7df0ac178e7be019c90
name: F6B668D80E37F7DF0AC178E7BE019C90.mlw
sha1: 463f263f827d161961610d6ec52f362f8c69fb62
sha256: cafd721e0b70b3c7d31a8e986bd77a1965ff3227a9dae270d478bb82d10532d6
sha512: 3c1654d5d721c8ef32c70cc02e9574f25632a3ee49151568ea4b1f4da5ed4c0eb6b3d7c37f542458905efd83bff7b0af8583aa7eddcdc59318ff17a9f7959f8a
ssdeep: 3072:TG9txRzFIUQj/+2jKPAHIcYVf1OpE6Z5hIWL0TW+L:y9txRFaj31GMpE6Z5NiL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.1141245565 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Papras.2867
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.Ransom.GlobeImposter
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Gandcrab.ecaa0b99
K7GWTrojan ( 005204461 )
Cybereasonmalicious.80e37f
CyrenW32/S-e64ad02f!Eldorado
SymantecRansom.CryptXXX
ESET-NOD32Win32/Filecoder.FV
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Emotet-6397345-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Crypmod.evyibn
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentMalware.Win32.Gencirc.10ba7da8
Ad-AwareTrojan.BRMon.Gen.4
SophosML/PE-A + Mal/Ransom-FN
ComodoTrojWare.Win32.Crypt.BF@7gchou
BitDefenderThetaGen:NN.ZexaF.34722.iuW@a0UZN6t
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_FAKEGLOBE.CBQ
McAfee-GW-EditionBehavesLike.Win32.Upatre.ch
FireEyeGeneric.mg.f6b668d80e37f7df
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.dum
WebrootW32.Trojan.Emotet
AviraHEUR/AGEN.1106539
MicrosoftRansom:Win32/Gandcrab.SF!MTB
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.N
AhnLab-V3Trojan/Win32.MalCrypted.R215263
Acronissuspicious
McAfeeTrojan-FOUO!F6B668D80E37
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Crypmod
MalwarebytesMalware.AI.1141245565
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_FAKEGLOBE.CBQ
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!4bZryVk2TA4
IkarusTrojan-Ransom.FileCrypter
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/Kryptik.GASG!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Malware.AI.1141245565?

Malware.AI.1141245565 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment