Malware

About “Malware.AI.3927583826” infection

Malware Removal

The Malware.AI.3927583826 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3927583826 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.jiandwg.cn
a.tomx.xyz

How to determine Malware.AI.3927583826?


File Info:

crc32: 05CFDD19
md5: 1ec6f46ada74dcdcd40411909f9eb9f6
name: 1EC6F46ADA74DCDCD40411909F9EB9F6.mlw
sha1: fa101b5ca06bd9781ed16cedc6781c03edfe00a9
sha256: 2cc2aaba16fb66b1797ff51c484f4eacaf3e6bff747c00f39311aff610ce9dd3
sha512: c2b4410c21a8187a5a39a9cb2a1722a0bed35061215c803406f4e5d8488506fa82519262bbd16d0dcf9193e20ce5e5392836729d4b2e6a3d3ad850861192f24b
ssdeep: 12288:sk64yG6yHld+AUG1ixVbRWKvTatpFyE4Tb5EIkIQ:3B+KixVbRWFLyEg5EIfQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: www.jiandwg.cn
FileVersion: 1.0.0.1
CompanyName: www.jiandwg.cn
Comments: www.jiandwg.cn
ProductName: x4f20x5947x591ax5f00
ProductVersion: 1.0.0.1
FileDescription: x7b80x5355x591ax5f00x5de5x5177
Translation: 0x0804 0x04b0

Malware.AI.3927583826 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader7.24472
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.ca06bd
CyrenW32/FlyStudio.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Flystudio-6937682-0
KasperskyTrojan-Downloader.Win32.Genome.djds
TencentWin32.Trojan-downloader.Genome.Ecuw
SophosGeneric PUA PK (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureTrojan:W32/Agent.DQOD
VIPRETrojan.Win32.Autorun.dm (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.1ec6f46ada74dcdc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_65%
Antiy-AVLGrayWare/Win32.FlyStudio.b
KingsoftWin32.Troj.Generic.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-Downloader.Win32.Genome.djds
GDataWin32.Trojan.FlyStudio.A
AhnLab-V3Worm/Win32.FlyStudio.C230697
McAfeeArtemis!1EC6F46ADA74
MalwarebytesMalware.AI.3927583826
PandaTrj/CI.A
YandexTrojan.DL.Genome!EwKLBpaiHuU
IkarusTrojan.Win32.FlyAgent
MaxSecureTrojan.Autorun.DM
FortinetW32/Generic.AP.14793D8!tr
AVGWin32:Malware-gen

How to remove Malware.AI.3927583826?

Malware.AI.3927583826 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment