Malware

Malware.AI.3521953650 (file analysis)

Malware Removal

The Malware.AI.3521953650 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3521953650 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Malware.AI.3521953650?


File Info:

crc32: E5B01675
md5: f6460e8f0d2b4518ff1612353726f429
name: F6460E8F0D2B4518FF1612353726F429.mlw
sha1: 7535189daedf407cc7c16e37181534a1bedeaa54
sha256: 237d1f9d2b7ba1de48b5abd5749c426508f5af42fef440ff27a3d4aa12064104
sha512: d4771b4a52fd39b16d64c17f3537e8215fd7c809cdd1462852b0a7b0923935a0188e610ac87fb3bcd66729fb4471c86e8562247d58851d3c4c6b568163fa3053
ssdeep: 6144:CwM3aNTWYzGhfOQT/9WFmL8SZ6c67rXHVLmoAL6kjBUFqjf1ahmD4ogM3P4IfBs:rMI1zs2Q/9wSB4XjAljmAL1jgMwI277
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Likumasese Ltd. xa9 2012-2016 All Rights Reserved
InternalName: nisefamfenat
FileVersion: 1.2.30.56
CompanyName: Likumasese Ltd.
LegalTrademarks:
ProductName: Gomamo Gapoded
ProductVersion: 2.4.25.70
FileDescription: Rem Kuh
OriginalFilename: nisefamfenat.exe
Translation: 0x0409 0x04b0

Malware.AI.3521953650 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 00529a881 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealAdware.Dealply.ZZ8
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00529a881 )
Cybereasonmalicious.f0d2b4
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/DealPly.OY.gen potentially unwanted
APEXMalicious
AvastFileRepMetagen [PUP]
Kasperskynot-a-virus:HEUR:RiskTool.Win32.MAgentKill.12950581.gen
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Dealply.Ebzy
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
ComodoMalware@#3x7zattavfko
BitDefenderThetaAI:Packer.0638739416
TrendMicroPUA_DEALPLY.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.f6460e8f0d2b4518
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Genome.ccbl
AviraHEUR/AGEN.1126495
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.1DBE3A3
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
Acronissuspicious
McAfeeArtemis!F6460E8F0D2B
MAXmalware (ai score=60)
MalwarebytesMalware.AI.3521953650
PandaTrj/GdSda.A
TrendMicro-HouseCallPUA_DEALPLY.SM
RisingAdware.DealPly!1.AA42 (CLASSIC)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGFileRepMetagen [PUP]

How to remove Malware.AI.3521953650?

Malware.AI.3521953650 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment