Malware

What is “Malware.AI.879715358”?

Malware Removal

The Malware.AI.879715358 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.879715358 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.879715358?


File Info:

crc32: 5BD8F8AA
md5: fa730e428cf503fc8d3049c73fbab5d3
name: FA730E428CF503FC8D3049C73FBAB5D3.mlw
sha1: 92fd30e8f1fb131f7a8c2fcba11a7cc3f096b6ed
sha256: 249d1200d90633785e22d5fb7e9dec59b15119833699c8394ba3c5b4d2c13c01
sha512: afed0086a43cc94fc226a5562c0b748fe83a233b6644beee17256f501385324ce3110003f91d4a29c0c151adda5512d0a836cb5b1d3c46cc83c75f309863653b
ssdeep: 12288:fcQrmVGJrfrtPXXa4d5jz4Ox2E+3IX8FgfFI:fcQrmVGRrdRd5/4Ox9u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Todos os direitos reservados para JDSOFT SISTEMAS - 2002
InternalName: nova.exe
FileVersion: 2.1.0.23
CompanyName: JDSOFT SISTEMAS LTDA ME
LegalTrademarks: Todos os direitos reservados para JDSOFT SISTEMAS - 2002
Comments: Software de Atualizaxe7xe3o - JDSOFT
ProductName: Nova JDSOFT
ProductVersion: 2.1.0.23
FileDescription: Software de atualizaxe7xe3o
OriginalFilename: frm_Nova
Translation: 0x0416 0x04e4

Malware.AI.879715358 also known as:

K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Graftor.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Graftor.554162
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.28cf50
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Graftor.554162
MicroWorld-eScanGen:Variant.Graftor.554162
TencentWin32.Trojan.Spy.Eeqt
Ad-AwareGen:Variant.Graftor.554162
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZelphiF.34266.zO0baK3g@KmO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Graftor.554162
EmsisoftGen:Variant.Graftor.554162 (B)
AviraTR/Spy.Banker.Gen
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Graftor.554162
AhnLab-V3Malware/Win32.Generic.C2661697
McAfeeArtemis!FA730E428CF5
MAXmalware (ai score=93)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.879715358
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!d+NLbpmLvfQ
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.879715358?

Malware.AI.879715358 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment