Malware

Malware.AI.4127092775 (file analysis)

Malware Removal

The Malware.AI.4127092775 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4127092775 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.4127092775?


File Info:

crc32: 39043748
md5: a2c2a81a98df2744b5fca06b6816423a
name: A2C2A81A98DF2744B5FCA06B6816423A.mlw
sha1: ca9f33c921aec1952ebd10e13d1d073ae7727b9e
sha256: dd287c0fa4775b14d380266b6b019781c01a9aa75410661e7d278a68b20b8559
sha512: 94efdb714efff9f1704c2a8e077087d251eacf743d60143d510a814f5133370c2de22f8d158c4553935420aa8f45d8103e8a74ae965062e727634d1caf755d99
ssdeep: 3072:ggLJdATD5BqMdcj/7kdQMgLPYUgwSxpAw:ggdd2VBqXnkK3LAUgwS
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998-2011 Tencent. All Rights Reserved
InternalName: QQMusic
FileVersion: 7.84.1992.307
CompanyName: Tencent
PrivateBuild: QQMusic
LegalTrademarks: Tencent
Comments: QQMusic2010
ProductName: 7.84.1992.307
SpecialBuild:
ProductVersion:
FileDescription: QQMusic
OriginalFilename: QQMusic.exe
Translation: 0x0804 0x04b0

Malware.AI.4127092775 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.32935
MicroWorld-eScanGen:Variant.Ursu.779168
FireEyeGeneric.mg.a2c2a81a98df2744
McAfeeArtemis!A2C2A81A98DF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.Ursu.779168
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaCO.34804.iq1@aOlaH8hb
CyrenW32/Trojan.IM1.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Farfli-689
KasperskyTrojan-GameThief.Win32.Magania.tzqa
NANO-AntivirusTrojan.Win32.Magania.cqputg
ViRobotTrojan.Win32.A.PSW-Magania.135168.BO
AegisLabTrojan.Win32.Generic.lut8
TencentWin32.Trojan-gamethief.Magania.Lmuc
Ad-AwareGen:Variant.Ursu.779168
SophosMal/Generic-S
ComodoTrojWare.Win32.Farfli.LK@4pmigc
F-SecureTrojan.TR/Spy.Gen7
BaiduWin32.Trojan.Farfli.ap
ZillyaTrojan.Magania.Win32.43458
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Ursu.779168 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:TrojanDropper.TDSS
WebrootW32.Trojan.Gen
AviraTR/Spy.Gen7
Antiy-AVLTrojan[GameThief]/Win32.Magania
MicrosoftBackdoor:Win32/Farfli.O
ArcabitTrojan.Ursu.DBE3A0
ZoneAlarmTrojan-GameThief.Win32.Magania.tzqa
GDataGen:Variant.Ursu.779168
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Jorik.R20134
VBA32TrojanPSW.Magania
ALYacGen:Variant.Ursu.779168
MAXmalware (ai score=81)
MalwarebytesMalware.AI.4127092775
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Farfli.HF
RisingBackdoor.Farfli!1.6531 (CLASSIC)
YandexTrojan.Farfli!4nXSJFBkJ/o
IkarusBackdoor.Inject
eGambitUnsafe.AI_Score_100%
FortinetW32/Farfli.HF!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.a98df2
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.6e8

How to remove Malware.AI.4127092775?

Malware.AI.4127092775 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment