Malware

Malware.AI.3690236759 malicious file

Malware Removal

The Malware.AI.3690236759 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3690236759 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.3690236759?


File Info:

name: CD66CA7BB7341A3C4D9F.mlw
path: /opt/CAPEv2/storage/binaries/8125352d7eb1c2fc6f34c8e7f8acbd0e30a7ffbe8383bb3fb92171b8e05444fd
crc32: D0500322
md5: cd66ca7bb7341a3c4d9fa658a5e71252
sha1: f2f5d572ee9d3513de7cca8e689d91922f21b2fa
sha256: 8125352d7eb1c2fc6f34c8e7f8acbd0e30a7ffbe8383bb3fb92171b8e05444fd
sha512: 5285c4b17da63b4e2c165f46393ea3fa6054acaa3710b34812d2ecc143dabeef3992fd482657331d242093af70c231105255bde44ddb464af1d0673dda2a54c3
ssdeep: 12288:9aytPVHlX5D0W5MlrM8NTStRNU/jrJKgorV0J+YS7mO40FdXrv:DPFrD0W5Mcf0rJK5E/SyO42dXD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127E4230A0168ED63F698437E864CCEA22E0DB036153AA743E7FAC1571DBC7D991067ED
sha3_384: d4bbee75cbe5f08975f571897c7c20fbabf6510c2f45c838e482ae1829838b7c1cc25297736e091a6892c8c433360290
ep_bytes: 60be008059008dbe0090e6ffc78710bc
timestamp: 2013-04-02 04:32:25

Version Info:

CompanyName: Fepokekusun Ltd.
FileDescription:
FileVersion: 1.8.43.39
InternalName: Tokopo
LegalCopyright: Fepokekusun Ltd. All Rights Reserved
LegalTrademarks:
OriginalFilename: tokoporudoca.exe
ProductName: Gogacu Gatapukel
ProductVersion: 2.5.19.26

Malware.AI.3690236759 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.DealPly.2.Gen
FireEyeAdware.DealPly.2.Gen
McAfeeArtemis!CD66CA7BB734
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0053f9621 )
BitDefenderAdware.DealPly.2.Gen
K7GWAdware ( 0053f9621 )
Cybereasonmalicious.bb7341
BitDefenderThetaGen:NN.ZelphiF.34062.OmKfamtXqZbi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.TP potentially unwanted
APEXMalicious
AlibabaAdWare:Win32/DealPly.a5dfa25a
NANO-AntivirusRiskware.Win32.DealPly.iryonf
TencentWin32.Adware.Dealply.Taos
Ad-AwareAdware.DealPly.2.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
EmsisoftAdware.DealPly.2.Gen (B)
SentinelOneStatic AI – Malicious PE
GDataAdware.DealPly.2.Gen
JiangminAdWare.DealPly.nrgy
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1201179
Antiy-AVLTrojan/Generic.ASMalwS.307A8B1
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DealPly.C2694420
VBA32Adware.DealPly
MAXmalware (ai score=67)
MalwarebytesMalware.AI.3690236759
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
RisingAdware.DealPly!1.AA42 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AGEN.1033829!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.3690236759?

Malware.AI.3690236759 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment