Malware

Malware.AI.2209133302 information

Malware Removal

The Malware.AI.2209133302 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2209133302 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Malware.AI.2209133302?


File Info:

name: 2C216E89FC7F574F3799.mlw
path: /opt/CAPEv2/storage/binaries/fd6ef44f13621d9a7c2dbc60cafac155b20c84689e763946104d2e3d8c2fb2d8
crc32: 7C119A33
md5: 2c216e89fc7f574f37990dd7c96b862b
sha1: aacc71075a02fdf91aecfc8517874b8771fa58ce
sha256: fd6ef44f13621d9a7c2dbc60cafac155b20c84689e763946104d2e3d8c2fb2d8
sha512: 2f4382083c8ad52b255b914bbb010b9f0e968057e3bd6881b37cbeaab36ab123d44337789f788b7df75ee4f008400e2a9f23d0d7fc59fdf15e580ed25d452b54
ssdeep: 24576:fAHnh+eWsN3skA4RV1Hom2KXMmHa78n5:Ch+ZkldoPK8Ya7o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8058B0273D2D036FFAB92739B6AB20596BD79250133852F13981DB9BD701B1273E663
sha3_384: 325798ed02307ac6e1e906a2a963136eef7f2cc320a2f043790e5104e8ac3e7e5fa798e0f17b68ee41e7c0741e29c599
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2020-12-29 11:15:40

Version Info:

Comments: gEKRfrbSpl
CompanyName: FmFTQvpfaOPkAvOUHhMPF
FileDescription: kIgCuS
FileVersion: 9.4.1.8
InternalName: MBwObLdLBqrF
LegalCopyright: rejEWwrHTQus
LegalTrademarks: eUcfWkuXMOn
ProductName: gURSteKPud
ProductVersion: 1.1.2.1
Translation: 0x0809 0x04b0

Malware.AI.2209133302 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.KT.2.Zu0@aecv!hai
FireEyeGen:Trojan.Heur.KT.2.Zu0@aecv!hai
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0056a9891 )
K7GWTrojan ( 0056a9891 )
Cybereasonmalicious.9fc7f5
CyrenW32/AutoIt.SR.gen!Eldorado
ESET-NOD32a variant of Win32/Autoit.OIW
APEXMalicious
KasperskyUDS:Trojan.Win32.Agent.xapqmj
BitDefenderGen:Trojan.Heur.KT.2.Zu0@aecv!hai
AvastAutoIt:Runner-BH [Trj]
Ad-AwareGen:Trojan.Heur.KT.2.Zu0@aecv!hai
EmsisoftGen:Trojan.Heur.KT.2.Zu0@aecv!hai (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
AviraWORM/FakeExt.Gen8
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.KT.2.Zu0@aecv!hai
CynetMalicious (score: 99)
BitDefenderThetaAI:Packer.EE12DF1621
ALYacGen:Trojan.Heur.KT.2.Zu0@aecv!hai
MalwarebytesMalware.AI.2209133302
RisingMalware.FakeFolder/ICON!1.D519 (CLASSIC)
IkarusTrojan.Win32.Autoit
FortinetW32/Autoit.OHL!tr
AVGAutoIt:Runner-BH [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.2209133302?

Malware.AI.2209133302 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment