Malware

About “Malware.AI.1561254581” infection

Malware Removal

The Malware.AI.1561254581 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1561254581 virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates Zeus (Banking Trojan) mutexes
  • Zeus P2P (Banking Trojan)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
denatgruel.com
yandex.ru

How to determine Malware.AI.1561254581?


File Info:

crc32: 42C7F359
md5: f41373c4658b3bf74965918d3a26a983
name: F41373C4658B3BF74965918D3A26A983.mlw
sha1: ec92c5dc79835b02a8ad00efc4474cd82cb7178b
sha256: e0989ae86a8b481892c40f87d08c0848b68abcd938959e35f4524d5dcc75fa4b
sha512: 435cc47e9066599cb3ab28858078402911f103679459e031cca070b6ecb1e10079bc8b01f3701eaf449d919d86dfb580d0efc70c9ace8be066429957f01b1c0f
ssdeep: 3072:tu4rWMYhsXsVxF9Xp7jU+b9Lv8zhbly8GyXk:Ho/VxRP8zh2Ik
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.1561254581 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 004dcbc41 )
LionicTrojan.Win32.Panda.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.11620
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Dreidel.gqW@xaryHUe
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.209523
SangforTrojan.Win32.XPACK.Gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Panda.038b8b7d
K7GWSpyware ( 004dcbc41 )
Cybereasonmalicious.4658b3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Zbot.ACM
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Panda-9814670-1
KasperskyTrojan-Spy.Win32.Panda.dtq
BitDefenderGen:Heur.Mint.Dreidel.gqW@xaryHUe
NANO-AntivirusTrojan.Win32.Panda.gcptxr
ViRobotTrojan.Win32.Z.Zbot.111616.DV
MicroWorld-eScanGen:Heur.Mint.Dreidel.gqW@xaryHUe
TencentWin32.Trojan.Crypt.Eacp
Ad-AwareGen:Heur.Mint.Dreidel.gqW@xaryHUe
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.gqW@aaryHUe
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PGU21
McAfee-GW-EditionBehavesLike.Win32.VTFlooder.ch
FireEyeGeneric.mg.f41373c4658b3bf7
EmsisoftGen:Heur.Mint.Dreidel.gqW@xaryHUe (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.2C7241C
MicrosoftTrojan:Win32/Occamy.B
ArcabitTrojan.Mint.Dreidel.E84F09
GDataGen:Heur.Mint.Dreidel.gqW@xaryHUe
AhnLab-V3Trojan/Win32.ZBot.R294543
Acronissuspicious
McAfeeGenericRXDT-RI!F41373C4658B
MAXmalware (ai score=82)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesMalware.AI.1561254581
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PGU21
RisingRansom.Satan!1.AEB7 (CLASSIC)
YandexTrojan.GenAsa!vBrt6DhzJVQ
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.74072838.susgen
FortinetW32/Generic.AP.1916D0!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.1561254581?

Malware.AI.1561254581 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment