Malware

Malware.AI.1477932987 information

Malware Removal

The Malware.AI.1477932987 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1477932987 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.1477932987?


File Info:

crc32: 0441A968
md5: 16c33c7d49e556b6d858fbd3c5e6bf0f
name: 16C33C7D49E556B6D858FBD3C5E6BF0F.mlw
sha1: 9ab2417795b23c0d4f2e697cf234a00fc9e80329
sha256: 2039a4fed3e7d93974c9be58bd60d1cdcf0508b4e3175b60090e17c6221ee65e
sha512: 1054112eb6deb8a1254b65eb555fabae09562a8d3e786ee130dd517264a3e5e9236537614d0d8132f92b9b015f6ff6eec7c696351da594fcd25dcc0b46adc55f
ssdeep: 49152:d12luHByvZHc8l1YEg7/z2TNPk5jTlj+Ky9NJ5V59xHiPXkPmr7+VbPFI:L8uh2ZdYEOz2TNPk5jTllkfV59xHiPU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.1477932987 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00534e281 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.11410
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Doina.892
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojanDropper:Win32/GenKryptik.ba8f091c
K7GWTrojan ( 00534e281 )
Cybereasonmalicious.d49e55
CyrenW32/S-3d12273a!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastFileRepMalware
ClamAVWin.Malware.Roxer-9858231-0
KasperskyHEUR:Trojan-Dropper.Win32.Roxer.gen
BitDefenderGen:Variant.Doina.892
NANO-AntivirusTrojan.Win32.Razy.fjxfdk
MicroWorld-eScanGen:Variant.Doina.892
TencentMalware.Win32.Gencirc.10b3ed5a
Ad-AwareGen:Variant.Doina.892
SophosMal/Generic-R
ComodoMalware@#akzt8p16w6py
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.16c33c7d49e556b6
EmsisoftGen:Variant.Doina.892 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.qxgs
AviraHEUR/AGEN.1141220
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28FE0B1
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataGen:Variant.Doina.892
AhnLab-V3PUP/Win32.Agent.R248624
Acronissuspicious
McAfeeArtemis!16C33C7D49E5
MAXmalware (ai score=87)
VBA32BScope.Trojan.Jobutyve
MalwarebytesMalware.AI.1477932987
PandaTrj/Genetic.gen
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ZSH!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Malware.AI.1477932987?

Malware.AI.1477932987 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment