Malware

Malware.AI.3460258888 (file analysis)

Malware Removal

The Malware.AI.3460258888 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3460258888 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Malware.AI.3460258888?


File Info:

crc32: C06BDE17
md5: e9007d84b1073b522c190c2a8acebb88
name: E9007D84B1073B522C190C2A8ACEBB88.mlw
sha1: 2e79d96fb2710e7412dd4309224def76359076e2
sha256: dc4e69c9371dee3b3a7039b4a3d8ec021d40b91fe10a6301c6d96bea87f78f1b
sha512: 8db8a393dba84ec5b3d9ee5915d1dc586cfe7ed8336945b8a9857ac5fd930b8ac0e4cae0360fe43d19eb6c95f830b77471c976520d90757fafae0d5a2d35dba4
ssdeep: 6144:FkMrXLwdYwhnegTRKslBtMdnI37N3pIpSAYXrk1nWjDG1NoG+JLuS:rwdYw1DMNe7JGb91yGy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 2011-2017
InternalName: Gitiho
FileVersion: 2.4.47.98
CompanyName: Heremat Ltd.
LegalTrademarks:
ProductName: Becesopub Pobaseboh 43 Doba
ProductVersion: 3.6.11.87
FileDescription:
OriginalFilename: GitihoDogini.exe

Malware.AI.3460258888 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 00529a881 )
LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
ZillyaAdware.DealPly.Win32.198244
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderAdware.DealPly.1.Gen
K7GWAdware ( 00529a881 )
Cybereasonmalicious.4b1073
BitDefenderThetaGen:NN.ZelphiF.34170.smKfaulDfici
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DealPly.VS potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaAdWare:Win32/DealPly.00676bb4
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Generic.Airg
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#rlku0n0oq5n4
TrendMicroPUA_DEALPLY.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.e9007d84b1073b52
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126504
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.211BCEE
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.DealPly.gen
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C1929957
Acronissuspicious
McAfeeArtemis!E9007D84B107
MAXmalware (ai score=97)
VBA32Adware.DealPly
MalwarebytesMalware.AI.3460258888
TrendMicro-HouseCallPUA_DEALPLY.SM
RisingAdware.DealPly!1.AA42 (CLASSIC)
IkarusPUA.DealPly
FortinetAdware/DealFly
PandaTrj/Genetic.gen

How to remove Malware.AI.3460258888?

Malware.AI.3460258888 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment