Malware

MSIL/DomaIQ.P potentially unwanted removal instruction

Malware Removal

The MSIL/DomaIQ.P potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/DomaIQ.P potentially unwanted virus can do?

  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid

How to determine MSIL/DomaIQ.P potentially unwanted?


File Info:

name: 831FE278215FCCA35B25.mlw
path: /opt/CAPEv2/storage/binaries/7a19030ab932a63e1d6facc331ee2add06143fc581e9f6c6585eecab6c94d552
crc32: 3E188A1B
md5: 831fe278215fcca35b2591bd81bfc398
sha1: b1b37650a6ff8208968d95c3f89fcf52fdafaf0d
sha256: 7a19030ab932a63e1d6facc331ee2add06143fc581e9f6c6585eecab6c94d552
sha512: 997314ce7bb525f81545474777344aa0c87dbf8eb5ab3a0b2edb843f936527da063ce64a4c47cba0b2bd56f3e9c80245d659a681977013e85380132109664e9e
ssdeep: 384:JntNJbIhrNSH+nVuDAM7axGIhzFvA45pUVI0dyDMI0G0DCt8:JtzuQH6VwXaNXA4oLd80b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180B22B8E579CE527C67DA77994B20902127493176193EB0F6CC8B5F2CCA33A229177C7
sha3_384: ad6630e0a4bd16e855bd5215bd0ac165ce60f400e242e7ddb54ad920f249ce0e792a4fe3c18f2e7449a84188e8e37ba9
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-01-03 13:31:02

Version Info:

Translation: 0x0000 0x04b0
FileDescription: mmbcsheekx
FileVersion: 4.0.6.191
InternalName: setup.exe
LegalCopyright:
OriginalFilename: setup.exe
ProductVersion: 4.0.6.191
Assembly Version: 4.0.6.191

MSIL/DomaIQ.P potentially unwanted also known as:

BkavW32.Common.81DFB54F
LionicTrojan.Win32.Disfa.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.65248775
SkyhighBehavesLike.Win32.Dropper.mm
McAfeeRDN/Real Protect-LS
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_60% (W)
VirITTrojan.Win32.Generic.BCAC
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/DomaIQ.P potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.65248775
NANO-AntivirusTrojan.Win32.Adw.ddqexe
AvastWin32:PUP-gen [PUP]
RisingTrojan.Generic!8.C3 (CLOUD)
EmsisoftTrojan.GenericKD.65248775 (B)
F-SecurePotentialRisk.PUA/DomaIQ.bsouena
VIPRETrojan.GenericKD.65248775
TrendMicroTROJ_GEN.R002C0OK223
FireEyeGeneric.mg.831fe278215fcca3
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.65248775
JiangminTrojan/Generic.bircw
WebrootW32.Trojan.MSIL.Disfa
AviraPUA/DomaIQ.bsouena
Antiy-AVLTrojan/MSIL.Disfa
KingsoftWin32.Trojan.Generic.a
XcitiumMalware@#25klvhalj3zgj
ArcabitTrojan.Generic.D3E39E07
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.A!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Blocker.R93565
ALYacTrojan.GenericKD.65248775
MalwarebytesMalware.AI.2265706301
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.R002C0OK223
TencentMalware.Win32.Gencirc.13b9f359
YandexTrojan.Disfa!Qd1OjrKWHrw
IkarusPUA.DomaIQ
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.JAX!tr
BitDefenderThetaGen:NN.ZemsilF.36680.bm0@aGm70Tg
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.0a6ff8
DeepInstinctMALICIOUS

How to remove MSIL/DomaIQ.P potentially unwanted?

MSIL/DomaIQ.P potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment