Malware

Should I remove “Malware.AI.2205340187”?

Malware Removal

The Malware.AI.2205340187 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2205340187 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Malware.AI.2205340187?


File Info:

name: D065BA3A592CBE374442.mlw
path: /opt/CAPEv2/storage/binaries/4ca7f7562f851d39b0a49ac45d08bbf9da46409821ba83854d05664b9dfec383
crc32: A66BEEF3
md5: d065ba3a592cbe3744421e87944df52c
sha1: cac1f0c4eecabb8318efce7daa7603f23543c1d6
sha256: 4ca7f7562f851d39b0a49ac45d08bbf9da46409821ba83854d05664b9dfec383
sha512: 9582061c7a9b1c89a2099beeeedfed413c9f90ce12491000ca264b65685c27f8b3eb86d5175ec2cf48010616b3618469006b8468e7bf23d0f3564f0a2c448f54
ssdeep: 6144:trBU3RPqmoE38tV+5xJ9E204c2uFFTGXWAYQ6XHmhPDEp45pL+6C:2RuE3A+1NpuzTGmHQAHWpL+6C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEC4AF11B3D40C72E9BB467889675B06D7FABC121624DB4F53908E9A1F33352BB29353
sha3_384: f70fc94e648c4d1a899de39dedaa6b629b7fcec7e6862fc13ebbf782d1390b68286c600706b4d6cf322766f7b4a758e4
ep_bytes: e85bfeffff33c0c3558bec5633c057bf
timestamp: 2021-12-10 02:54:16

Version Info:

0: [No Data]

Malware.AI.2205340187 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeGenericRXKB-SV!D065BA3A592C
CylanceUnsafe
ZillyaTrojan.Invader.Win32.2190
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan-Downloader ( 004fbdbc1 )
K7AntiVirusTrojan-Downloader ( 004fbdbc1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Carberp.BU
APEXMalicious
ClamAVWin.Dropper.Miner-7086570-0
KasperskyHEUR:Trojan.Win32.Invader
BitDefenderDeepScan:Generic.Ursnif.3.1.12EB0199
NANO-AntivirusTrojan.Win32.Invader.flxezl
MicroWorld-eScanDeepScan:Generic.Ursnif.3.1.12EB0199
AvastWin32:RATX-gen [Trj]
Ad-AwareDeepScan:Generic.Ursnif.3.1.12EB0199
EmsisoftDeepScan:Generic.Ursnif.3.1.12EB0199 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.d065ba3a592cbe37
SophosML/PE-A
IkarusTrojan.Win32.PSW
GDataDeepScan:Generic.Ursnif.3.1.12EB0199
JiangminTrojan.Generic.alinp
AviraTR/Hijacker.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2A36D6F
ArcabitDeepScan:Generic.Ursnif.3.1.12EB0199
MicrosoftTrojan:Win32/Tnega.BBL!MTB
AhnLab-V3Trojan/Win32.Generic.R369614
Acronissuspicious
VBA32BScope.Trojan.Invader
ALYacDeepScan:Generic.Ursnif.3.1.12EB0199
MAXmalware (ai score=86)
MalwarebytesMalware.AI.2205340187
RisingTrojan.Generic@ML.100 (RDML:Qr/SXIyov1bZgVkT1M7htg)
YandexTrojan.GenAsa!MesJDakHGlQ
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AP.14B7886!tr
BitDefenderThetaGen:NN.ZexaF.34084.HqW@aGKUQMm
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.a592cb
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.2205340187?

Malware.AI.2205340187 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment