Malware

About “Application.Imonetize.2 (B)” infection

Malware Removal

The Application.Imonetize.2 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Imonetize.2 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Application.Imonetize.2 (B)?


File Info:

name: 8FDCA13F3DE0F00100B7.mlw
path: /opt/CAPEv2/storage/binaries/5546ced5b0aa72b8613f6c0c301fa41f288acab492734c3ba9943bd91b5ad121
crc32: E929A88A
md5: 8fdca13f3de0f00100b720b92fbe76f7
sha1: e3530e1fce9e655c5c1c9e48db934e94a88176c5
sha256: 5546ced5b0aa72b8613f6c0c301fa41f288acab492734c3ba9943bd91b5ad121
sha512: b68d511eb52e9a0712d4311c814a3a936a8c415726bc7af1228e146118b567467c556eee0d6500a79186ac3f5005cee2b8cc8ea61485066492f5e6b0e3786386
ssdeep: 24576:vqdm6tsKB2MHpyhgr3G3TPpxX2KWMRJM8l0Ws6:vqkKMMH5r4T/b0k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C02533D5E016CCA1C1A44D31C81889FA2CDABE15D6CDABB7AB107CA5F6F7D803511E1E
sha3_384: 718bf2765ec73fb7d8eabd5a479acdf50513f596ae8f1868e80f599fbaa5a6fab8b1f149eec362371fb6956c5ae77922
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2016-02-02 08:13:45

Version Info:

0: [No Data]

Application.Imonetize.2 (B) also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Application.Imonetize.2
FireEyeGeneric.mg.8fdca13f3de0f001
McAfeeGenericRXMS-EU!8FDCA13F3DE0
CylanceUnsafe
ZillyaTrojan.Black.Win32.45758
K7AntiVirusAdware ( 004db3121 )
BitDefenderGen:Application.Imonetize.2
K7GWAdware ( 004db3121 )
CrowdStrikewin/grayware_confidence_100% (W)
ArcabitApplication.Imonetize.2
BaiduWin32.Trojan.Kryptik.aax
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Amonetize.OT potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
Kasperskynot-a-virus:VHO:AdWare.Win32.Convagent.gen
Ad-AwareGen:Application.Imonetize.2
SophosGeneric ML PUA (PUA)
DrWebAdware.Downware.14750
VIPREGen:Application.Imonetize.2
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Application.Imonetize.2 (B)
IkarusPUA.Amonetize
JiangminAdWare.Amonetize.gvb
AviraADWARE/Amonetize.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.39E8
GDataGen:Application.Imonetize.2
BitDefenderThetaGen:NN.ZexaF.34646.9mraauhzarai
ALYacGen:Application.Imonetize.2
MAXmalware (ai score=78)
VBA32Downloader.AdLoad
MalwarebytesMalware.AI.3418682966
PandaTrj/CI.A
TencentMalware.Win32.Gencirc.10c46dc5
YandexPUA.Amonetize!v6LK+3+Cm9g
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Amonetize
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.f3de0f
AvastWin32:Adware-gen [Adw]

How to remove Application.Imonetize.2 (B)?

Application.Imonetize.2 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment