Malware

Malware.AI.3914877951 removal

Malware Removal

The Malware.AI.3914877951 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3914877951 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.3914877951?


File Info:

crc32: 8C744526
md5: 69bae34d111b7ecfc42322e75ee31669
name: 69BAE34D111B7ECFC42322E75EE31669.mlw
sha1: 4541717d1be98d645851cee540ff9b169fa61263
sha256: 218c4be1aed7d65908fbb02029dbcc5e5ba26188f78c19cc97ff82b243a0fbc3
sha512: b1fccc0c1808d7acc718ac8a936489b9598629e782b51da1b48ec744b74a0ed862053b1c364df10d82f1b3996bb2099cd1016a1a0495ec2389feed5bf0adab09
ssdeep: 6144:lok4d6SMH80iFowtvkxiaeMw8slj5NDO1aI1n5lRsktwmh/JxZcmFn:2fdzMc0VwqiaE8slj+1l1n5bSm/Zcon
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Nebefakopo Ltd.
InternalName: DanoheCigas
FileVersion: 2.4.38.73
CompanyName: Nebefakopo Ltd.
LegalTrademarks:
ProductName: Pecebatuh Lema
ProductVersion: 2.4.3.17
FileDescription:
OriginalFilename: DanoheCigas.exe
Translation: 0x04b0 0x04e4

Malware.AI.3914877951 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 00529a881 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealAdware.Dealply.ZZ8
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.102899
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 00529a881 )
Cybereasonmalicious.d111b7
CyrenW32/DealPly.BJ.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/DealPly.XH potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Generic.Wrha
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
ComodoApplicUnwnt@#3o31ysz3wqfio
BitDefenderThetaAI:Packer.1D33F92819
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.69bae34d111b7ecf
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Genome.ccbl
AviraHEUR/AGEN.1126495
Antiy-AVLTrojan/Generic.ASMalwS.1E230DB
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
Acronissuspicious
McAfeeArtemis!69BAE34D111B
MAXmalware (ai score=61)
VBA32Adware.DealPly
MalwarebytesMalware.AI.3914877951
PandaTrj/GdSda.A
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.Agent!Hjv9EYh4S64
IkarusAdWare.DealPly
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.3914877951?

Malware.AI.3914877951 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment