Malware

What is “Malware.AI.766209235”?

Malware Removal

The Malware.AI.766209235 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.766209235 virus can do?

  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Malware.AI.766209235?


File Info:

crc32: 562D4FE8
md5: b1d3d2abcbd3ecd01a25133241a398c9
name: B1D3D2ABCBD3ECD01A25133241A398C9.mlw
sha1: bd4f66a1578dded544a39f9061fe909fe8c8ce92
sha256: cf59e335211a8425a2f9d10f8ac732671870f5cf06fa2b47c0a8386ec4398cdc
sha512: 13dc7f043882a0f8135ccde97061025043779c55871cf8c78b8b97956dfaeb42ae761c57e5e13c5e571522a93daf27a5ff95aff4bdac9ee9386a387ae05ff73b
ssdeep: 12288:Co8CT66JyUIVmt/IwUyqo7Aom4kwwVMxmRc/a:JurUUmt/IwUy8orYMyc/a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: HetalKirug
FileVersion: 1.8.18.67
CompanyName: Gedufaf Ltd.
LegalTrademarks:
ProductName: Muhuhudum Rakose 33
ProductVersion: 2.7.15.87
FileDescription: Gehog
OriginalFilename: HetalKirug.exe
Translation: 0x0409 0x04e4

Malware.AI.766209235 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 005393151 )
LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTool.Bundler.Win32.5552
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/DealPly.a3707d73
K7GWAdware ( 005393151 )
Cybereasonmalicious.bcbd3e
CyrenW32/DealPly.U.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DealPly.WC potentially unwanted
APEXMalicious
AvastWin32:DealPly-AJ [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderAdware.DealPly.1.Gen
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanAdware.DealPly.1.Gen
TencentMalware.Win32.Gencirc.10b75194
Ad-AwareAdware.DealPly.1.Gen
SophosDealPly Updater (PUA)
BitDefenderThetaGen:NN.ZelphiF.34170.HK0@aGbSdHai
VIPRETrojan.Win32.Generic!BT
TrendMicroAdware.Win32.DEALPLY.SMD
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.b1d3d2abcbd3ecd0
EmsisoftAdware.DealPly.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.mwty
AviraHEUR/AGEN.1125473
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2462DA4
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitAdware.DealPly.1.Gen
SUPERAntiSpywarePUP.DealPly/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataAdware.DealPly.1.Gen
AhnLab-V3PUP/Win32.DealPly.R228908
Acronissuspicious
McAfeeGenericRXAA-AA!B1D3D2ABCBD3
MAXmalware (ai score=99)
VBA32Adware.Presenoker
MalwarebytesMalware.AI.766209235
PandaTrj/Genetic.gen
TrendMicro-HouseCallAdware.Win32.DEALPLY.SMD
RisingAdware.DealPly!1.AA42 (CLASSIC)
YandexRiskware.Agent!TCYsYYzzjDE
IkarusPUA.DealPly
FortinetAdware/Generic
AVGWin32:DealPly-AJ [Adw]
Paloaltogeneric.ml

How to remove Malware.AI.766209235?

Malware.AI.766209235 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment