Malware

Malware.AI.2125989368 (file analysis)

Malware Removal

The Malware.AI.2125989368 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2125989368 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Malware.AI.2125989368?


File Info:

crc32: F2F55356
md5: bbbfeb5d83341f92d9dca8ddc57eca3f
name: BBBFEB5D83341F92D9DCA8DDC57ECA3F.mlw
sha1: 052293260aad2bfe8a137c46c50fbcc74e5f7769
sha256: 5f1f09adbfdd6229486df2d4ef6ec974a4e595e852da47c8f06b286874fc480e
sha512: a2075314d1f3750733c058e88eedb904f5ccd4644cdbba61fdc15c8a3c1e67ae358f297cf113a57b7ea162cc41b1058433e0aec2c7845163f0ef061754a05aea
ssdeep: 24576:Pg6Jn3jZKNK8wfTxEvb/lJZLbEZsD0hPBSSBnu+S9t5XqeO7k5moVNgG:40jubNz9UP4SBn5eXqHkPrg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright All Rights Reserved
InternalName: gonecadori
FileVersion: 3.2.41.4
CompanyName: Gakulahad Ltd.
LegalTrademarks:
ProductName: Garifefu
ProductVersion: 3.7.47.83
FileDescription:
OriginalFilename: gonecadori.exe

Malware.AI.2125989368 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 005497bb1 )
Elasticmalicious (high confidence)
DrWebAdware.DealPly.1867
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaAdware.DealPly.Win32.99738
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.9269eddf
K7GWAdware ( 005497bb1 )
Cybereasonmalicious.d83341
CyrenW32/DealPly.AI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.RB potentially unwanted
APEXMalicious
AvastWin32:DealPly-AJ [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.bynev
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusRiskware.Win32.DealPly.extars
ViRobotAdware.Dealply.2282496.QS
MicroWorld-eScanAdware.DealPly.1.Gen
TencentMalware.Win32.Gencirc.10b17245
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
BitDefenderThetaAI:Packer.D3BBD2A719
VIPRETrojan.Win32.Generic!BT
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.bbbfeb5d83341f92
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.hodi
AviraHEUR/AGEN.1104226
eGambitUnsafe.AI_Score_75%
Antiy-AVLTrojan/Generic.ASMalwS.2459EFD
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C2403396
Acronissuspicious
McAfeeGenericR-PAI!BBBFEB5D8334
MAXmalware (ai score=63)
VBA32Adware.DealPly
MalwarebytesMalware.AI.2125989368
PandaTrj/Genetic.gen
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
YandexPUA.DealPly!wEMLDClf31c
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DealPly
AVGWin32:DealPly-AJ [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.2125989368?

Malware.AI.2125989368 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment