Malware

Should I remove “Malware.AI.1154334020”?

Malware Removal

The Malware.AI.1154334020 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1154334020 virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1154334020?


File Info:

name: 899FB390F7600F0DB3A3.mlw
path: /opt/CAPEv2/storage/binaries/b175590b1d8a818bcde50c56801def51926876ab5dc20c3a1724c116a0c2e9ee
crc32: 166C9173
md5: 899fb390f7600f0db3a32727901743f0
sha1: 1589bebb8271c441b14fd0bde4e4deba6a119d4a
sha256: b175590b1d8a818bcde50c56801def51926876ab5dc20c3a1724c116a0c2e9ee
sha512: c16cddfdca5bbc6700d0bab7567ee4d6c63eb560f9287af9b3856acb4cca7c7453becc2d6c2d2b821915d74af7e92130fed7195cf5d93e1d1c4e9f8c9dd0509d
ssdeep: 6144:PxB1ZyF4tGahWNwgfye620XLRCGBxN0Uw9Uu6nqoxrpDZ3aFE7/:PxI4tF9Sh6zXtXeUwOr/b
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T19654AF3E5BDC9D03E7CD5778E8D7019083B0BA127583E79B201D3AA56E9B3A19D1428F
sha3_384: 6d587dea9a8ae401d44cdd25742ba33f8c2fc102c57297fce12e62a241d47c6069f1bc245bdd1a115d21c7e0563f3756
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-08-13 08:04:54

Version Info:

Translation: 0x0000 0x04b0
FileDescription: PKTuBsOY
FileVersion: 4.0.6.6
InternalName: tmp.dll
LegalCopyright: dwfoaAIlLch
LegalTrademarks: qRBirvPR
OriginalFilename: tmp.dll
ProductName: LiRElmW
ProductVersion: 4.0.6.6
Assembly Version: 4.0.6.6

Malware.AI.1154334020 also known as:

LionicTrojan.MSIL.Disco.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.73
MicroWorld-eScanTrojan.GenericKD.47575691
McAfeeArtemis!899FB390F760
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 00574e2d1 )
AlibabaTrojanPSW:MSIL/Disco.40fd96bc
K7GWTrojan ( 00574e2d1 )
Cybereasonmalicious.b8271c
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Packed.VMProtect.C suspicious
TrendMicro-HouseCallTROJ_GEN.R002H07L621
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
BitDefenderTrojan.GenericKD.47575691
AvastWin64:PWSX-gen [Trj]
TencentMsil.Trojan-qqpass.Qqrob.Eckt
Ad-AwareTrojan.GenericKD.47575691
EmsisoftTrojan.GenericKD.47575691 (B)
McAfee-GW-EditionBehavesLike.Win64.RAHack.dc
FireEyeGeneric.mg.899fb390f7600f0d
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47575691
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1144755
MAXmalware (ai score=82)
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D2D5F28B
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32TrojanPSW.MSIL.Disco
ALYacTrojan.GenericKD.47575691
MalwarebytesMalware.AI.1154334020
APEXMalicious
IkarusTrojan.MSIL.Vmprotect
MaxSecureTrojan.Malware.115904540.susgen
FortinetRiskware/Application
AVGWin64:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1154334020?

Malware.AI.1154334020 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment