Malware

Malware.AI.1154081042 removal guide

Malware Removal

The Malware.AI.1154081042 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1154081042 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1154081042?


File Info:

crc32: 4C3CE55B
md5: 8c56e65d11ba840ba0f729693c45e1ca
name: 8C56E65D11BA840BA0F729693C45E1CA.mlw
sha1: 2de34f07ae182461a3b3942a0c5c233f987d53e4
sha256: 21827c14d1c195a779520a95f8958845a8fa04a3c7e3193198ac2f014caa68bb
sha512: 50e24022a8ee78343251b91814a39317765320a184c04670bce36ccb425f232b48da5d520ad14947e133bc785c484b45b0c0bbb8e57cb6b82a51658c1cb8373c
ssdeep: 3072:15qwKOGsgD2Bmz9E9b/BotKOrQnPBs6hlNMFLGW7y9tGTzeXMk9G+c23twd:
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: WinInit
FileVersion: 10.0.15063.502 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.15063.502
FileDescription: Windows Start-Up Application
OriginalFilename: WinInit.exe
Translation: 0x0409 0x04b0

Malware.AI.1154081042 also known as:

K7AntiVirusTrojan ( 00541f391 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.46236
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.167529
CylanceUnsafe
SangforTrojan.MSIL.Kryptik.QCI
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Bladabindi.ef38ae59
K7GWTrojan ( 00541f391 )
Cybereasonmalicious.d11ba8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.QCI
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Bulz.167529
NANO-AntivirusTrojan.Win32.Bladabindi.fkrrvg
MicroWorld-eScanGen:Variant.Bulz.167529
TencentWin32.Trojan.Ursu.Ecao
Ad-AwareGen:Variant.Bulz.167529
SophosMal/Generic-S
ComodoMalware@#1e5cm4sb3c2gh
BitDefenderThetaGen:NN.ZemsilF.34294.Im1@a0SrySbi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R007C0PGF21
McAfee-GW-EditionBehavesLike.Win32.Generic.hz
FireEyeGeneric.mg.8c56e65d11ba840b
EmsisoftGen:Variant.Bulz.167529 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.rsvre
eGambitUnsafe.AI_Score_93%
Antiy-AVLTrojan/Generic.ASMalwS.28CC11F
MicrosoftTrojan:Win32/Occamy.C21
ArcabitTrojan.Bulz.D28E69
GDataGen:Variant.Bulz.167529
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=83)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.1154081042
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R007C0PGF21
YandexTrojan.Kryptik!IgehqQ10w98
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.11825261.susgen
FortinetMSIL/Kryptik.QCI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1154081042?

Malware.AI.1154081042 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment