Malware

Malware.AI.1709954680 removal

Malware Removal

The Malware.AI.1709954680 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1709954680 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.1709954680?


File Info:

name: 2A1084BF7117B1792323.mlw
path: /opt/CAPEv2/storage/binaries/2929b663ab844d5acd4ac47416ce000a465deed837aa4884e0cbb4943a030388
crc32: CFA23957
md5: 2a1084bf7117b1792323506eb38729b1
sha1: a0ff80b2a73146000be78e9eec8679e60e28203f
sha256: 2929b663ab844d5acd4ac47416ce000a465deed837aa4884e0cbb4943a030388
sha512: 498c3522e55f5be241aa60dd2c2f8e11650e99497f2015c7971cbe0be1501dd7a830952c265080e7ff5a5d3a513deeedcc5e710f70b1b8be0aa39558b3200dbc
ssdeep: 6144:g9xAc20AgaDo61neauFLLEJ5mZFieax4GyxSLEdYBhcoGfhTJYUa2UyH:amcugaDoinxuFvqmZFFxSLPhc7pT+3Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB542261BCC7D935F5F0C736CBC117ABF5207456D64AAA17BE8C128B39682082F26B74
sha3_384: 118a14c5af5cdbed81bd3578d00f638338ec1b729a7e21246dd1f59cb6cc73a6fe1f23188ac841941e88c6d1f7504144
ep_bytes: 60be006044008dbe00b0fbffc787d084
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Kagetup Ltd.
FileDescription: Sofuhot
FileVersion: 1.3.5.61
InternalName: fereric
LegalCopyright:
LegalTrademarks: 2009-2015
OriginalFilename: fereric.exe
ProductName: Dukorolof Tiga Pohoba
ProductVersion: 3.4.46.55

Malware.AI.1709954680 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.2a1084bf7117b179
CAT-QuickHealAdware.DealPly.AL8
MalwarebytesMalware.AI.1709954680
ZillyaAdware.DealPly.Win32.210007
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Win32/DealPly.32e65b62
K7GWAdware ( 00529a881 )
K7AntiVirusAdware ( 00529a881 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DealPly.LH.gen potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
AvastWin32:Adware-gen [Adw]
TencentWin32.Adware.Generic.Hqbo
EmsisoftAdware.DealPly.1.Gen (B)
ComodoApplicUnwnt@#2mir642ix3n8s
TrendMicroPUA_DEALPLY.SM
McAfee-GW-EditionBehavesLike.Win32.Worm.dc
SophosDealPly Updater (PUA)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1109242
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Occamy.C29
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.DealPly.gen
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C1925762
McAfeeGenericRXAA-AA!2A1084BF7117
MAXmalware (ai score=100)
TrendMicro-HouseCallPUA_DEALPLY.SM
RisingPUF.DealPly!1.AA42 (CLOUD)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
BitDefenderThetaAI:Packer.54E7CCB221
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.f7117b

How to remove Malware.AI.1709954680?

Malware.AI.1709954680 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment