Malware

What is “Malware.AI.3791105865”?

Malware Removal

The Malware.AI.3791105865 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3791105865 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3791105865?


File Info:

crc32: 6F816D6D
md5: 8318b0138c8c370a1f5d2fd038db2762
name: 8318B0138C8C370A1F5D2FD038DB2762.mlw
sha1: 56d10489bfb56be82eb53a9c925b32a6ba0188a2
sha256: 5b6b3c078251d60eeb58f1bdbce640643ea195622589aec7dd3e02c97218b8bb
sha512: a85ad09e2ac6d9f077b8580ba5f4d7f76340b7c2d35dd6553adf1738e90b9b4c9099f28e97448131af0df98787cd4cb4fb14750ccd79f7ec2386e14a3e7e7327
ssdeep: 6144:S7hB4yBhEpfZOgj6yz+7A/ECHcfOTo+gU0NzbwcSHH0QSlhCtkl1uFyIhTSVsde:SlZmhOguyzlxcfOThgU0lbwcSHIlh5l
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: Lemu
FileVersion: 2.6.47.35
CompanyName: Somekemitol Ltd.
LegalTrademarks:
ProductName: Mibufudu Ranob Keherel
ProductVersion: 1.5.4.50
FileDescription: Dosu Lab
OriginalFilename: Lemu.exe

Malware.AI.3791105865 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 0053f9621 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaAdware.DealPly.Win32.203147
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.70ca5468
K7GWAdware ( 0053f9621 )
Cybereasonmalicious.38c8c3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.UA potentially unwanted
APEXMalicious
AvastWin32:Evo-gen [Susp]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agent.gen
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.ixfnhj
MicroWorld-eScanAdware.DealPly.2.Gen
TencentMalware.Win32.Gencirc.114d80bf
Ad-AwareAdware.DealPly.2.Gen
SophosGeneric PUA FG (PUA)
BitDefenderThetaGen:NN.ZelphiF.34170.xmKfaKQDT1fi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUPXGK.fc
FireEyeGeneric.mg.8318b0138c8c370a
EmsisoftAdware.DealPly.2.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112084
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitAdware.DealPly.2.Gen
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Agent.gen
GDataAdware.DealPly.2.Gen
AhnLab-V3PUP/Win32.DealPly.C2638059
McAfeeArtemis!8318B0138C8C
MAXmalware (ai score=100)
VBA32Adware.Puwaders
MalwarebytesMalware.AI.3791105865
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.Agent!yoKbInVGB/A
IkarusTrojan-Downloader.Win32.Banload
FortinetRiskware/DealPly
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Malware.AI.3791105865?

Malware.AI.3791105865 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment