Malware

Malware.AI.1603771891 removal guide

Malware Removal

The Malware.AI.1603771891 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1603771891 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

csdw.jia-si.cn
downdcdn.jia-si.cn
www.jia-si.cn

How to determine Malware.AI.1603771891?


File Info:

crc32: 74BD8276
md5: c986a7e763ebaead1ac405808faa5194
name: C986A7E763EBAEAD1AC405808FAA5194.mlw
sha1: 14871d743455de49e94e86a8625e7e25aa298424
sha256: 206b56fcf823f8f8d37dd1fd95b911185522470566757286bede345fa62da08f
sha512: eaf470dda6417017c7ea0298bb6c40a597b165c85095233d4e6afb3d5e768f6c406f15195a38ed948b8d34b2768aa341b4518d9fe07282babd51b842a62bf183
ssdeep: 49152:XHdqjoA1+/EIjOmNof5ALhEMjdpk2mSLTK8nEKUXzyPKuqL20T:Xc1+hOpBzMjX7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.1603771891 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00535f0d1 )
Elasticmalicious (high confidence)
DrWebAdware.Softcnapp.92
CynetMalicious (score: 100)
CAT-QuickHealDownldr.Adload.S3351678
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1401051
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00535f0d1 )
Cybereasonmalicious.43455d
CyrenW32/S-d2a266d3!Eldorado
SymantecPUA.Downloader
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Softcnapp.fhswuw
TencentTrojan.Win32.Generic.e
SophosSoftcnapp (PUA)
ComodoApplication.Win32.AdWare.Softcnapp.O@80ok4p
BitDefenderThetaGen:NN.ZexaF.34294.KAW@aGNZlPmj
McAfee-GW-EditionBehavesLike.Win32.Softcnapp.vh
FireEyeGeneric.mg.c986a7e763ebaead
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cnusx
AviraHEUR/AGEN.1142834
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27A3BF2
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AhnLab-V3PUP/Win32.Helper.R233980
Acronissuspicious
McAfeeSoftcnapp
MAXmalware (ai score=100)
VBA32BScope.Adware.Puwaders
MalwarebytesMalware.AI.1603771891
PandaTrj/Genetic.gen
RisingAdware.Downloader!1.BBEC (CLASSIC)
YandexTrojan.GenAsa!j9wp91EzKUE
IkarusPUA.Softcnapp
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Softcnapp
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.1603771891?

Malware.AI.1603771891 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment