Malware

About “Malware.AI.3897990295” infection

Malware Removal

The Malware.AI.3897990295 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3897990295 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3897990295?


File Info:

crc32: A62A3B25
md5: 06e8c95e895b8a2bcfa910fd4eb84853
name: 06E8C95E895B8A2BCFA910FD4EB84853.mlw
sha1: 4b4577931af9f064301b6c2249913547c9dec1b6
sha256: 1dbb081940c43907171727ab1f65f7a5920f2676ee8cf2d032f5672ed4be5e00
sha512: 9255feea4ea64418621a93b28e607b07e205dae7f1224a12eff7bf5d81d4aae8281aade2fa840bc4dbf919990d32a34b30c0a0d8fad09a00dc703114cc8eca68
ssdeep: 6144:SHCQoJuxTJt5NIZYLsDu2AJeLwSASK4L0wPjBnYxcLH/wdt8cUNb:SHGJyJTmasDu2AJekSAD9CLYdpUNb
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: Duhuh
FileVersion: 2.9.11.11
CompanyName: Sugamace
LegalTrademarks:
ProductName: Puhacip
ProductVersion: 2.2.35.88
FileDescription: Sah Geco
OriginalFilename: Duhuh.exe

Malware.AI.3897990295 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 005393151 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.7a2fcbbc
K7GWAdware ( 005393151 )
Cybereasonmalicious.e895b8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.UD potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.DealPly.gen
BitDefenderAdware.DealPly.2.Gen
NANO-AntivirusRiskware.Win32.DealPly.fkpudt
MicroWorld-eScanAdware.DealPly.2.Gen
TencentWin32.Adware.Dealply.Hpg
Ad-AwareAdware.DealPly.2.Gen
SophosGeneric PUA EL (PUA)
ComodoMalware@#18hk5t6875wyn
BitDefenderThetaGen:NN.ZelphiF.34266.rmKfaKhRZZmi
VIPRETrojan.Win32.Generic!BT
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Gnamer.dc
FireEyeGeneric.mg.06e8c95e895b8a2b
EmsisoftAdware.DealPly.2.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.DealPly.jvmg
AviraHEUR/AGEN.1118676
Antiy-AVLTrojan/Generic.ASMalwS.29B1DC6
MicrosoftPWS:Win32/Zbot!ml
GDataAdware.DealPly.2.Gen
AhnLab-V3PUP/Win32.RL_DealPly.R294609
Acronissuspicious
McAfeeArtemis!06E8C95E895B
VBA32Adware.DealPly
MalwarebytesMalware.AI.3897990295
PandaTrj/Genetic.gen
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
RisingAdware.DealPly!1.AA42 (CLASSIC)
IkarusPUA.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agen.9714!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.3897990295?

Malware.AI.3897990295 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment