Malware

Malware.AI.2421380070 removal tips

Malware Removal

The Malware.AI.2421380070 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2421380070 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.2421380070?


File Info:

name: 7DA6BBE82FDA09FDCEF7.mlw
path: /opt/CAPEv2/storage/binaries/536cccd6bf8f539da2beca16907de2d8da7e5cd6618215915ea22401a19c5879
crc32: 68C55178
md5: 7da6bbe82fda09fdcef746ef89fc2977
sha1: 2021279c7cf92e918bb026cc02c10af7410a1b49
sha256: 536cccd6bf8f539da2beca16907de2d8da7e5cd6618215915ea22401a19c5879
sha512: 9171503c23719fe738517c278d2ee158e013b04e28a1fc072310583f4711a64a3b140f4dc361634a481e37d6f3f5570c5a08f6cee033a8556b6fb8cd2a8712b7
ssdeep: 24576:+3IthDQ8qo8EX9yFBPStfjTGi2JqdZ6t6AWl:GRvpS0ieqdZ6AAW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103156B13B284583BD0661A365C678360693F7A7C2A96FC573EE40D0E0F792A12D3EB57
sha3_384: d0e16ca8d78263085ef3e0e16c8236122eb2b31efd3f12f6a56678bbfb7d8d423dfb86f19612a5b4c867d6742638fd1d
ep_bytes: 558bec83c4f0b8a00f4d00e83837f3ff
timestamp: 2013-01-09 01:25:44

Version Info:

CompanyName: Sinacotal
FileDescription: Rebulo Pefucake
FileVersion: 2.5.2.21
InternalName: Pasofob
LegalCopyright:
LegalTrademarks:
OriginalFilename: PasofobTudoled.exe
ProductName: Depakinap Reto
ProductVersion: 2.6.25.93

Malware.AI.2421380070 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.2.Gen
FireEyeGeneric.mg.7da6bbe82fda09fd
McAfeeGenericRXAA-AA!7DA6BBE82FDA
MalwarebytesMalware.AI.2421380070
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00533e0a1 )
K7AntiVirusAdware ( 00533e0a1 )
ArcabitAdware.DealPly.2.Gen
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/DealPly.QN potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:AdWare.Win32.DealPly
BitDefenderAdware.DealPly.2.Gen
ViRobotAdware.Dealply.929280.HS
AvastWin32:DealPly-AJ [Adw]
Ad-AwareAdware.DealPly.2.Gen
EmsisoftAdware.DealPly.2.Gen (B)
ZillyaAdware.DealPly.Win32.392457
TrendMicroTROJ_GEN.R002C0OGQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosGeneric PUA CA (PUA)
IkarusPUA.DealPly
AviraHEUR/AGEN.1112083
Antiy-AVLTrojan/Generic.ASMalwS.3064122
GridinsoftRansom.Win32.Zbot.oa
MicrosoftProgram:Win32/Wacapew.C!ml
SUPERAntiSpywarePUP.DealPly/Variant
GDataAdware.DealPly.2.Gen
AhnLab-V3PUP/Win32.DealPly.C3269049
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34160.4O0@aiB4Aoei
MAXmalware (ai score=60)
VBA32Adware.DealPly
TrendMicro-HouseCallTROJ_GEN.R002C0OGQ21
RisingPUF.DealPly!1.AA42 (C64:YzY0OqkjTNqbk5WH)
YandexRiskware.Agent!rG3FAxeKbxY
SentinelOneStatic AI – Malicious PE
FortinetRiskware/DealPly
AVGWin32:DealPly-AJ [Adw]
Cybereasonmalicious.82fda0
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.73560392.susgen

How to remove Malware.AI.2421380070?

Malware.AI.2421380070 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment