Malware

Malware.AI.2190635553 removal tips

Malware Removal

The Malware.AI.2190635553 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2190635553 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
enternet.ddns.net

How to determine Malware.AI.2190635553?


File Info:

crc32: 7D42CDDF
md5: ed5861d186e11ef68b7ec8865434247a
name: ED5861D186E11EF68B7EC8865434247A.mlw
sha1: 94f318d96d0c96b7ff26cfc1a854062f9b0286e2
sha256: c82f697f3212324c240075c3296682449628613e8d73d2eb1fdb0dc3e3304767
sha512: e63f1a8b5dfbac7496b1cd88a488843e52b56b8cf37f67e89c401106e92cc66f06c209c00f8e24846010989603545e65363d3a13f2b0f0df1767cfe2b3982853
ssdeep: 3072:l9C3wXJI8bavb32GhNvHtb1oqMwTzw0xe5MW8mIrYIRaLU:Xc2GhNdgM5QU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 x754cx6700x9ad898x6b73x30e8x30acx30a4x30f3x30b9x30c8x3046x306ax67d4 2017
Assembly Version: 12.44.21.33
InternalName: weeew.exe
FileVersion: 14.32.17.11
CompanyName: x30b9x30c8x30e9x30afx30bfx3088x3046x306ax67d4x8edfx3055
ProductName: x4e16x754cx6700x9ad8x9f62x306e98x6b73x30e8x30acx30a4
ProductVersion: 14.32.17.11
FileDescription: x5c11x5973x306ex3088x3046x306ax67d4x8edfx3055
OriginalFilename: weeew.exe

Malware.AI.2190635553 also known as:

K7AntiVirusTrojan ( 00502a641 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen3.53454
CynetMalicious (score: 99)
ALYacGen:Heur.MSIL.Abuja.1
CylanceUnsafe
SangforRansom.Win32.Blocker.jwjd
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 00502a641 )
Cybereasonmalicious.186e11
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.MZZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jwjd
BitDefenderGen:Heur.MSIL.Abuja.1
NANO-AntivirusTrojan.Win32.Blocker.ektkcs
MicroWorld-eScanGen:Heur.MSIL.Abuja.1
TencentWin32.Trojan.Blocker.Amce
Ad-AwareGen:Heur.MSIL.Abuja.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34058.sm0@aO8t68f
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.ed5861d186e11ef6
EmsisoftGen:Heur.MSIL.Abuja.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.ghb
AviraTR/AD.Bladabindi.secae
Antiy-AVLTrojan/Generic.ASMalwS.1E189AC
MicrosoftWorm:MSIL/Necast.H
ArcabitTrojan.MSIL.Abuja.1
GDataGen:Heur.MSIL.Abuja.1
McAfeeArtemis!ED5861D186E1
MAXmalware (ai score=100)
VBA32Hoax.Blocker
MalwarebytesMalware.AI.2190635553
PandaTrj/GdSda.A
YandexTrojan.Blocker!TcbXNiCtlpQ
IkarusTrojan.MSIL.Krypt
FortinetMSIL/GenKryptik.RBD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOQA

How to remove Malware.AI.2190635553?

Malware.AI.2190635553 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment