Malware

How to remove “Malware.AI.4153979153”?

Malware Removal

The Malware.AI.4153979153 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4153979153 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4153979153?


File Info:

crc32: FC39C443
md5: b395cf0f46b7c0b4e68f60bbee3624a6
name: B395CF0F46B7C0B4E68F60BBEE3624A6.mlw
sha1: 91b8dd4513e24bf877a33e5adf65e6640ce7c143
sha256: 1dfbd9af7e23e5c2e11fe848d03314c06dfe0811e1ac7f06ac556d0c8741908c
sha512: fb4543ce8a43913542d049f0e88a71b860f1aa54023fb5fa8c7acd312c3f04c9cc3beba879114dcc134f1463cd310e4dcafb63022f3d90fc2cccb8874640c7e7
ssdeep: 3072:A8FR8xw3qMCGGGGG+y5gHXsKu65N3H5a1Bn4gK/BBCGqBJZ:A878xLGGGGG+ypKuu0/cWTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2016 Glarysoft Ltd
InternalName: Report.exe
FileVersion: 5, 0, 0, 6
CompanyName: Glarysoft Ltd
ProductName: Glary Utilities
ProductVersion: 5, 0, 0, 1
FileDescription: Glarysoft Crash Report
OriginalFilename: CrashReport.exe
Translation: 0x0804 0x03a8

Malware.AI.4153979153 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d37f1 )
LionicTrojan.Win32.NetStream.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.65429
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ranapama.ABW
CylanceUnsafe
ZillyaTrojan.NetStream.Win32.305
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0053d37f1 )
Cybereasonmalicious.f46b7c
CyrenW32/Trojan.BUF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GTKI
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Dropper.Bunitu-9897412-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ranapama.ABW
NANO-AntivirusTrojan.Win32.Kryptik.flqqpi
MicroWorld-eScanTrojan.Ranapama.ABW
TencentMalware.Win32.Gencirc.10b7d8bb
Ad-AwareTrojan.Ranapama.ABW
SophosMal/Generic-S + Mal/Cerber-AM
ComodoTrojWare.Win32.TrojanProxy.Bunitu.JL@80mh7b
BitDefenderThetaGen:NN.ZexaF.34266.zq1@aqsHQmfj
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.TRICKBOT.SMB.hp
McAfee-GW-EditionGenericRXHC-GR!B395CF0F46B7
FireEyeGeneric.mg.b395cf0f46b7c0b4
EmsisoftTrojan.Ranapama.ABW (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.dypkh
AviraTR/AD.Bunitu.eomba
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASMalwS.2A0EB5D
MicrosoftRansom:Win32/CerberCrypt.PB!MTB
GDataTrojan.Ranapama.ABW
AhnLab-V3PUP/Win32.Agent.R250558
Acronissuspicious
McAfeeGenericRXHC-GR!B395CF0F46B7
MAXmalware (ai score=100)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.4153979153
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMB.hp
RisingTrojan.Kryptik!1.B56C (CLASSIC)
YandexTrojan.GenAsa!UH2cMIV8h/s
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GLWT!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.4153979153?

Malware.AI.4153979153 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment