Malware

Malware.AI.2130639696 removal

Malware Removal

The Malware.AI.2130639696 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2130639696 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.2130639696?


File Info:

name: C9F0068555A4A1C08956.mlw
path: /opt/CAPEv2/storage/binaries/0606770cf59d9facbe6f8c908f0db73e2b482cc93ff637376f914f937b99a862
crc32: 13238223
md5: c9f0068555a4a1c0895676f17b69e1d8
sha1: ba0f75d06737cea0f95e7b8a370ee695c56ba4b0
sha256: 0606770cf59d9facbe6f8c908f0db73e2b482cc93ff637376f914f937b99a862
sha512: b0a527ea174a924c84d2b051cc2a66e2f9a65a73f1ccc91a2e77f195e1f2cdc2c83051f1e3001e8a0c70d35b295b403bd14ede1da1c2035ccefa9550a040e22b
ssdeep: 49152:p1WWPQZNlpPiSJUytWKJIb9PVCJ+g1WWPQZNlpPiSJUytWKJIb9PVCJ+:pZPQZ+yBJqiIgZPQZ+yBJqiI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149166D23B245253AC07F2A3A4927A554DD3FB7617A268C4F57F0886CCF398452E3E64B
sha3_384: a9909550c29addc3a657e21ae45e18256c86eaa76d11b00bc0bfaf677ba0c2b453c9f66e5a3caca534f13dfa8761d621
ep_bytes: 558bec83c4f0b810c85d00e83895e2ff
timestamp: 2013-09-02 09:44:02

Version Info:

0: [No Data]

Malware.AI.2130639696 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lrGb
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.2.Gen
ZillyaAdware.DealPly.Win32.384126
SangforVirus.Win32.Save.a
K7AntiVirusAdware ( 005341d51 )
AlibabaAdWare:Win32/DealPly.70cd6312
K7GWAdware ( 005341d51 )
Cybereasonmalicious.555a4a
CyrenW32/DealPly.BS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.QY potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.DealPly.fdgpd
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.iwrhoq
AvastWin32:DealPly-gen [Adw]
Ad-AwareAdware.DealPly.2.Gen
EmsisoftAdware.DealPly.2.Gen (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
FireEyeGeneric.mg.c9f0068555a4a1c0
SophosDealPly Updater (PUA)
SentinelOneStatic AI – Malicious PE
GDataAdware.DealPly.2.Gen
JiangminAdWare.DealPly.nfbz
AviraHEUR/AGEN.1201180
Antiy-AVLTrojan/Generic.ASMalwS.3033BB4
ArcabitAdware.DealPly.2.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DealPly.C1926484
Acronissuspicious
McAfeeArtemis!C9F0068555A4
MAXmalware (ai score=65)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesMalware.AI.2130639696
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexRiskware.Agent!SBepzQqn3M0
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealPly
AVGWin32:DealPly-gen [Adw]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.2130639696?

Malware.AI.2130639696 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment