Malware

Malware.AI.475492962 information

Malware Removal

The Malware.AI.475492962 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.475492962 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Malware.AI.475492962?


File Info:

crc32: DA2C06CA
md5: b58a31639b38ec938cc300e76b317515
name: B58A31639B38EC938CC300E76B317515.mlw
sha1: 3d10c0d8f1bb67a1b2cd60fd1f8d13ec2dbc51a6
sha256: 2cc6de33fbf2565fbdf7156a3f58fc244e1b0a84a665ccc95d08df97356c7210
sha512: be50e1a5b0c92c462ab9410de3ce377d3d7cf9ddbe33c5547a639b03c461a465ce92d7414d06efc354d15b53b2ceeb150d88e73244a878b84ecd973ded99ba03
ssdeep: 6144:4IUSs0/F97yNKED69zRejYVFqYkAw6VSwCI0wR5C0:4Qs0d9+qRnzqnW0
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName: Hehol
FileVersion: 3.4.12.93
CompanyName: Ketapadomimo
LegalTrademarks:
ProductName: Bebo Cimahed
ProductVersion: 3.5.36.70
FileDescription:
OriginalFilename: heholbetakak.exe

Malware.AI.475492962 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 00529a881 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealAdware.DealPly.AL8
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.89f5928c
K7GWAdware ( 00529a881 )
Cybereasonmalicious.39b38e
CyrenW32/DealPly.AG.gen!Eldorado
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/DealPly.KY.gen potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotAdware.Dealply.249856.NY
MicroWorld-eScanAdware.DealPly.1.Gen
TencentWin32.Adware.Generic.Pfje
Ad-AwareAdware.DealPly.1.Gen
SophosGeneric PUA DN (PUA)
ComodoApplicUnwnt@#19bmlyrqq2zwb
BitDefenderThetaAI:Packer.644ADBEB21
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.b58a31639b38ec93
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.lmah
AviraHEUR/AGEN.1142397
Antiy-AVLTrojan/Generic.ASMalwS.20FA352
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.C1929864
Acronissuspicious
McAfeeArtemis!B58A31639B38
MAXmalware (ai score=95)
VBA32Adware.DealPly
MalwarebytesMalware.AI.475492962
PandaTrj/Genetic.gen
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexPUA.Agent!EaIEyohxneA
FortinetAdware/DealFly
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.475492962?

Malware.AI.475492962 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment