Malware

Should I remove “Malware.AI.1149290336”?

Malware Removal

The Malware.AI.1149290336 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1149290336 virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1149290336?


File Info:

crc32: 88645816
md5: 56b11b66ae0a8aa40d6a9a88b983bed9
name: 56B11B66AE0A8AA40D6A9A88B983BED9.mlw
sha1: 97dfac337cf3b0ebe1607832cc3a6650fa89e3f6
sha256: 1db2bb0e34f2d6f9d7a212ff0833c71b66f60165be9cc36bca5af14ef9a2d9e0
sha512: 3d4a5ba1ca74243957bce6dbb978e0c1501cd161f67efd5be7c82c5ff8b0ad430b7c4cbff355ac9013e605017849dd1231d1233a1362feee178270c16080ea8c
ssdeep: 3072:fxdZ+RwPONXoRjDhIcp0fDlaGGx+cL/WEez+waQyJ8yNClcylEVLUEW:fvZ+RwPONXoRjDhIcp0fDlavx+W/WEU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: NE.NEWT1-55-7.xls.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: NE.NEWT1-55-7.xls.exe

Malware.AI.1149290336 also known as:

K7AntiVirusTrojan ( 0053564e1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.90819
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:MSIL/BadJoke.0211e0fd
K7GWTrojan ( 0053564e1 )
Cybereasonmalicious.6ae0a8
CyrenW32/MSIL_Injector.QL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/BadJoke.CP
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Razy.90819
NANO-AntivirusTrojan.Win32.Mlw.fejyli
MicroWorld-eScanGen:Variant.Razy.90819
TencentWin32.Trojan.Generic.Sxen
Ad-AwareGen:Variant.Razy.90819
SophosMal/Generic-S
ComodoMalware@#291uq92dlu0iy
BitDefenderThetaGen:NN.ZemsilF.34266.lm0@aiYtGwl
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
FireEyeGeneric.mg.56b11b66ae0a8aa4
EmsisoftGen:Variant.Razy.90819 (B)
AviraHEUR/AGEN.1105793
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Razy.90819
AhnLab-V3Trojan/Win32.Skeeyah.R231810
McAfeeGenericRXFY-VB!56B11B66AE0A
MAXmalware (ai score=98)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.1149290336
PandaTrj/GdSda.A
YandexTrojan.Agent!CWmocus/Bbg
SentinelOneStatic AI – Malicious PE
FortinetMSIL/BadJoke.CP!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.1149290336?

Malware.AI.1149290336 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment