Malware

About “W32.Infector.A5” infection

Malware Removal

The W32.Infector.A5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32.Infector.A5 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine W32.Infector.A5?


File Info:

crc32: 7F9D3C44
md5: 7137f9f0a86c0ee423e6f0a065acb004
name: 7137F9F0A86C0EE423E6F0A065ACB004.mlw
sha1: 741aaa603efde62b08a0bd311fbf81a287f4c1bd
sha256: 10e5fc31cb4189ce1e5dddd36d3491dc231f50ae8ca3c856446afa280421c94b
sha512: 5cc3e72cc138469921ebe881669bba0881a2192114e7634582b6f23cb2e9c4f944d3d2f9009f25a4ed1358ee84885a2c11c1f6e91ac264181898ce32afc9d24e
ssdeep: 96:gPRQKL+Z6+jDQG4NugfjAiQbrj92hSfe6Fk4s/QkLuc7OhPgGvOMnrPWuLu:gVAsGsMFrAhJNQkqc7OhOMn7Wuq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1992-2001 Microsoft Corp.
InternalName: ActMovie.exe
FileVersion: 6.05.2600.5512
CompanyName: Microsoft Corporation
DirectShow: DirectShow Setup Tool
ProductName: DirectShow
ProductVersion: 6.05.2600.5512
FileDescription: DirectShow Setup Tool
OriginalFilename: ActMovie.exe
Translation: 0x0409 0x04e4

W32.Infector.A5 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.FileInfector.am0@aeAm9Md
FireEyeGeneric.mg.7137f9f0a86c0ee4
CAT-QuickHealW32.Infector.A5
ALYacGen:Trojan.FileInfector.am0@aeAm9Md
K7AntiVirusVirus ( 00508e1d1 )
K7GWVirus ( 00508e1d1 )
Cybereasonmalicious.0a86c0
InvinceaML/PE-A + W32/HWorld-A
CyrenW32/Hematite.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Virus.Win32.Infector
BitDefenderGen:Trojan.FileInfector.am0@aeAm9Md
NANO-AntivirusVirus.Win32.Infector.emtrum
Ad-AwareGen:Trojan.FileInfector.am0@aeAm9Md
SophosW32/HWorld-A
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Siggen.29
TrendMicroTROJ_GEN.R06EC0DKI20
McAfee-GW-EditionBehavesLike.Win32.HWorld.zm
EmsisoftGen:Trojan.FileInfector.am0@aeAm9Md (B)
IkarusVirus.Win32.Agent
GDataGen:Trojan.FileInfector.am0@aeAm9Md
AviraTR/Patched.Gen
Antiy-AVLGrayWare/Win32.Kryptik.Hematite
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.FileInfector.ED4C1F
ZoneAlarmHEUR:Virus.Win32.Infector
MicrosoftVirus:Win32/Hematite.A
CynetMalicious (score: 100)
AhnLab-V3Virus/Win32.Hematite.R198137
Acronissuspicious
MAXmalware (ai score=82)
VBA32Win32.Virus.Unknown.Heur
CylanceUnsafe
ESET-NOD32a variant of Win32/Agent.NDM
TrendMicro-HouseCallTROJ_GEN.R06EC0DKI20
RisingVirus.Agent!1.B308 (CLASSIC)
FortinetW32/Agent.D17
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove W32.Infector.A5?

W32.Infector.A5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment