Malware

Malware.AI.2996785204 removal tips

Malware Removal

The Malware.AI.2996785204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2996785204 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.2996785204?


File Info:

crc32: 1C68CCC5
md5: d1d5f4bc5f94f9533a8793b65ed68619
name: D1D5F4BC5F94F9533A8793B65ED68619.mlw
sha1: 4dbd43b43e2a92a914a137643636272142a3830a
sha256: 23a014b360ede5d71e8337d14a595a716a26b948c454cb9d1db0a6db7a3da460
sha512: c6b7fbef2c14afc83cf438be801bfe680589c9db4ddb8d03169cb26de297e539e7dd564aa42fad9887405cb416dc32a3cbcfbd8eb8de0486433225f8d7022b13
ssdeep: 6144:8UfJiewO4XiQbETH0IV07sG9G8aglK8FK5aTzbIExL:8Uh4SJrZNwKMTz0E
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.2996785204 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 00529a881 )
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00529a881 )
Cybereasonmalicious.c5f94f
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DealPly.XH potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.DealPly.bffqp
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Wrqb
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric PUA EN (PUA)
F-SecureHeuristic.HEUR/AGEN.1126495
BitDefenderThetaGen:NN.ZelphiF.34294.tmGfaOKcUfc
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OKJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.d1d5f4bc5f94f953
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.mgsf
AviraHEUR/AGEN.1126495
eGambitUnsafe.AI_Score_99%
Antiy-AVLGrayWare[AdWare]/Win32.DealPly
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitAdware.DealPly.1.Gen
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.R232296
Acronissuspicious
McAfeeArtemis!D1D5F4BC5F94
MAXmalware (ai score=96)
MalwarebytesMalware.AI.2996785204
PandaTrj/GdSda.A
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.DealPly!UoqtR4XJuJU
IkarusTrojan.Jord
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.2996785204?

Malware.AI.2996785204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment