Malware

Should I remove “Malware.AI.651355774”?

Malware Removal

The Malware.AI.651355774 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.651355774 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.651355774?


File Info:

name: 7FC55CB3925984572B1C.mlw
path: /opt/CAPEv2/storage/binaries/27537c3acfa6f0f04b33e95ad2fa522a6ac1ad7c8e91c0bd4e3533fc52d4bc78
crc32: 448575B3
md5: 7fc55cb3925984572b1c51618787f2fc
sha1: c3ed8841662c12183ad8e795d94c4b36ef3662ba
sha256: 27537c3acfa6f0f04b33e95ad2fa522a6ac1ad7c8e91c0bd4e3533fc52d4bc78
sha512: bc20b2066fb4ae724f5aca4508fffeca1b4f7b944b739fa73de924c56b758071340d5f6311b50f2a73b8c61215981242999f355f96e282ce3d005f708cd9dabb
ssdeep: 49152:NCEwGZM4S0ipM3lhe1q0kcrwxevq2TdbICS:AEwGZWp0beAOraAdbICS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167752313BA4A5571E42A593600BA470FC36669293F33176B787CBB6ED77B2C14E13382
sha3_384: f84770932345f364563c67caebcb0feefd0683c1ae0389e4c93d8d780430df99e31074f21894fd8f38fec38da89e2a1e
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Kat Setup
FileVersion: 4.8.1.5
LegalCopyright: Installer Soft
ProductName: Kat
ProductVersion: 3.3
Translation: 0x0000 0x04b0

Malware.AI.651355774 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.DealPly.2!c
MicroWorld-eScanApplication.DealAgent.EES
ALYacApplication.DealAgent.EES
CylanceUnsafe
SangforAdware.Win32.DealPly.djnbl
AlibabaAdWare:Win32/InstallCore.460c721b
Cybereasonmalicious.392598
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32Win32/InstallCore.Gen.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CJT21
Kasperskynot-a-virus:AdWare.Win32.DealPly.djnbl
BitDefenderApplication.DealAgent.EES
NANO-AntivirusVirus.Win32.Gen.ccmw
SUPERAntiSpywarePUP.DealPly/Variant
Ad-AwareApplication.DealAgent.EES
SophosInnoMod (PUA)
ComodoApplicUnwnt@#2v649fns1pck7
DrWebTrojan.InstallCore.3436
McAfee-GW-EditionBehavesLike.Win32.PUPInstaller.tc
SentinelOneStatic AI – Suspicious PE
FireEyeApplication.DealAgent.EES
EmsisoftApplication.DealAgent.EES (B)
GDataWin32.Application.InstallCore.LR@gen
WebrootPua.Adware.Installcore
ArcabitApplication.DealAgent.EES
ViRobotAdware.Dealply.1653534
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.djnbl
MicrosoftTrojan:Win32/Occamy.C27
AhnLab-V3Malware/Gen.Generic.C2550284
Acronissuspicious
McAfeeArtemis!7FC55CB39259
MAXmalware (ai score=94)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesMalware.AI.651355774
RisingAdware.InstallCore!1.AB2C (CLASSIC)
YandexPUA.DealPly!XJ1k/buaY78
FortinetAdware/DealPly
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Malware.AI.651355774?

Malware.AI.651355774 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment