Malware

Malware.AI.173526620 (file analysis)

Malware Removal

The Malware.AI.173526620 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.173526620 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

udo.jxwan.com
cfg.jipinwan.com
dld.jxwan.com
redirector.gvt1.com

How to determine Malware.AI.173526620?


File Info:

crc32: 34DD4B00
md5: 916dcf8c48e11586b10fd9de449e1ad2
name: 916DCF8C48E11586B10FD9DE449E1AD2.mlw
sha1: a59acb2d6bf4fd70729f1009c4d586d559971a1c
sha256: 548237944887c97b4a842643d6dbef3e090378e7f25c5ba1108f428e0efce33b
sha512: 604c21fb0d4a1f7838e50adc9cb34afa7fd2ed03a15ad0eedae75c13a2c19de64ec76d6beba0f8d63e73a828ed291ebb181920a217f1e095254681b53d85aa01
ssdeep: 49152:jPGjDvBxkXBYZfU2ydnWmSDyFXX986EWD6jFI6hL:jMvBxkXB6U2ytWmFFXX+xWmjl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.173526620 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.128813
FireEyeGeneric.mg.916dcf8c48e11586
CAT-QuickHealTrojan.Generic
ALYacGen:Variant.Strictor.128813
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0054c57a1 )
BitDefenderGen:Variant.Strictor.128813
K7GWTrojan ( 0054c57a1 )
Cybereasonmalicious.c48e11
CyrenW32/S-d7209103!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_STRICTOR_GF0701B2.UVPM
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.3a759abf
NANO-AntivirusTrojan.Win32.Delf.fhtrsv
TencentWin32.Trojan.Generic.Hrez
Ad-AwareGen:Variant.Strictor.128813
SophosMal/Generic-S + Troj/AutoG-CX
ComodoMalware@#3j9d8t0rcmglv
F-SecureHeuristic.HEUR/AGEN.1103189
DrWebTrojan.DownLoader24.50086
ZillyaTrojan.Reconyc.Win32.20419
TrendMicroTROJ_STRICTOR_GF0701B2.UVPM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
EmsisoftGen:Variant.Strictor.128813 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Reconyc.gun
AviraHEUR/AGEN.1103189
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Reconyc
MicrosoftTrojanDropper:Win32/Delf.BL!MTB
ArcabitTrojan.Strictor.D1F72D
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Strictor.128813
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1875291
Acronissuspicious
McAfeeGenericRXBT-ZJ!916DCF8C48E1
VBA32BScope.Trojan.Graftor
MalwarebytesMalware.AI.173526620
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Delf.UEQ
RisingTrojan.StartPage!8.B (TFE:2:G6789Oz2PcS)
YandexTrojan.GenAsa!KgqKSFAoB0s
IkarusTrojan.Win32.Regrun
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.UEQ!tr
BitDefenderThetaGen:NN.ZexaF.34804.5PY@aecMiZib
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM16.0.F35F.Malware.Gen

How to remove Malware.AI.173526620?

Malware.AI.173526620 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment