Malware

Malware.AI.1856962928 removal tips

Malware Removal

The Malware.AI.1856962928 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1856962928 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1856962928?


File Info:

crc32: 2F4C5366
md5: cf36d2c3023138fe694ffe4666b4b1b2
name: CF36D2C3023138FE694FFE4666B4B1B2.mlw
sha1: 08cd6314e99d1091c71bc21b6da680522ca6a161
sha256: 06eb602792cbe8fd01002eb34898bfd78beac30ce2b0384bd90f64db95f72afc
sha512: b118ffc93f5a4be0f3e80cfdba4fda0af98d310db7a05d1ada1fdc6b7ca0f5041ab6132a227367215e3c4e66bf6f3aecec45caf625bb93609705ea25cfb66df3
ssdeep: 6144:kVrYjQf/KOgzTrMzWdKT1f/5dWDquH2sJgHvKr8e0:kVrZf/ATwzbS2mgPl
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.1856962928 also known as:

K7AntiVirusTrojan ( 0055e3e61 )
LionicVirus.Win32.Nakuru.n!c
Elasticmalicious (high confidence)
DrWebTrojan.Progman
ClamAVWin.Spyware.5162-2
ALYacTrojan.Nakuru.a
CylanceUnsafe
ZillyaVirus.Nakuru.Win32.2
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Nakuru.cfc11a0f
K7GWTrojan ( 0055e3e61 )
Cybereasonmalicious.302313
BaiduWin32.Backdoor.Delf.ae
CyrenW32/Backdoor.MOHR-0430
SymantecBackdoor.Delf
ESET-NOD32Win32/Delf.AXZ
APEXMalicious
AvastWin32:Delf-ESJ [Trj]
CynetMalicious (score: 100)
KasperskyVirus.Win32.Nakuru.a
BitDefenderTrojan.Generic.2022290
MicroWorld-eScanTrojan.Generic.2022290
TencentTrojan.Win32.Agent.agy
Ad-AwareTrojan.Generic.2022290
SophosMal/Generic-R + Troj/Delf-EVA
ComodoBackdoor.Win32.Delf.AXZ@23rm
BitDefenderThetaAI:Packer.099DB00720
VIPRETrojan.Win32.Generic!BT
TrendMicroPE_NAKURU.A-O
McAfee-GW-EditionBehavesLike.Win32.PUPXKT.dc
FireEyeGeneric.mg.cf36d2c3023138fe
EmsisoftTrojan.Generic.2022290 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.fdkw
WebrootW32.Trojan.Gen
AviraTR/Spy.Loops.A
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.29CCD
KingsoftWin32.Troj.Genome.tb.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Generic.2022290
AhnLab-V3Trojan/Win32.Xema.C32061
McAfeeW32/Kespo.a
MAXmalware (ai score=98)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.1856962928
PandaTrj/Ukurka.B
TrendMicro-HouseCallPE_NAKURU.A-O
RisingBackdoor.Delf.xzd (CLASSIC)
YandexTrojan.Delf!IxeU+lcth/M
IkarusVirus.Win32.Nakuru
MaxSecureVirus.Nakuru.A
FortinetW32/Delf.AXZ!tr.bdr
AVGWin32:Delf-ESJ [Trj]

How to remove Malware.AI.1856962928?

Malware.AI.1856962928 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment