Malware

What is “Malware.AI.260027489”?

Malware Removal

The Malware.AI.260027489 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.260027489 virus can do?

  • Injection (inter-process)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Malware.AI.260027489?


File Info:

crc32: F13FDB3A
md5: ec0199b3161399262649c75852fc0a08
name: EC0199B3161399262649C75852FC0A08.mlw
sha1: 6c7bd4f5d88e245fb129a18ca856657b4c4f7cf4
sha256: 238dc02783e26c2f89eed1e205a8227b266dbde8ee4ed44f8aedd1fa2fa4fa70
sha512: 49901509277f5dc2352cdf92c384a2f036e5f5eebdedac02c61c209582ce18c4a65b2a11fc88083ff605b17daac28a7fa904e3d9ec8c2bd6ced4511c4157ed33
ssdeep: 192:X5WLHZw9OpBoldVmxO98FiC4ld3UbWQ+thhhnQ:pWLZWOpCRmwd7zWchhhQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.260027489 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 000006401 )
LionicWorm.Win32.Fipp.lFNt
Elasticmalicious (high confidence)
DrWebBackDoor.MagicLink.13
CynetMalicious (score: 100)
CMCGeneric.Win32.ec0199b316!CMCRadar
ALYacGen:Variant.Doina.14732
CylanceUnsafe
ZillyaTrojan.CmjSpy.Win32.24
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanDropper:Win32/CmjSpy.393a0c97
K7GWTrojan ( 000006401 )
Cybereasonmalicious.316139
CyrenW32/Heuristic-257!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CmjSpy
APEXMalicious
AvastWin32:Small-HUBK [Trj]
KasperskyTrojan-Dropper.Win32.Small.km
BitDefenderGen:Variant.Doina.14732
NANO-AntivirusTrojan.Win32.Small.cqnfev
MicroWorld-eScanGen:Variant.Doina.14732
TencentMalware.Win32.Gencirc.114d0725
Ad-AwareGen:Variant.Doina.14732
SophosTroj/CmjSpy-V
ComodoTrojWare.Win32.TrojanDropper.Small.km0@1eqrk8
BitDefenderThetaGen:NN.ZexaF.34294.auX@ayP9LBfb
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
McAfee-GW-EditionBackDoor-WB.gen.b
FireEyeGeneric.mg.ec0199b316139926
EmsisoftGen:Variant.Doina.14732 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Small.avp
AviraTR/Hijacker.Gen
eGambitGeneric.Dropper
Antiy-AVLTrojan/Generic.ASMalwS.3A24D
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Doina.D398C
GDataGen:Variant.Doina.14732
AhnLab-V3Trojan/Win32.Xema.C37535
Acronissuspicious
McAfeeBackDoor-WB.gen.b
MAXmalware (ai score=98)
VBA32BScope.Trojan.Genome
MalwarebytesMalware.AI.260027489
PandaTrj/Genetic.gen
RisingBackdoor.Win32.Cmjspy.cl (CLASSIC)
YandexTrojan.GenAsa!DrsvttSTtPg
IkarusTrojan-Dropper.Win32.Small.KM
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Small.KM!tr
AVGWin32:Small-HUBK [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.260027489?

Malware.AI.260027489 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment