Malware

What is “Malware.AI.2220025972”?

Malware Removal

The Malware.AI.2220025972 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2220025972 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the PoisonIvy malware family

How to determine Malware.AI.2220025972?


File Info:

name: 473A738146ED6001245A.mlw
path: /opt/CAPEv2/storage/binaries/edea88d2ce28d89a9777ea160fbe41a12e50158a6f9c17511491c5293f1e3788
crc32: 31286451
md5: 473a738146ed6001245a68cd20c76b39
sha1: 5a14531808415e2364482070e1cd2a58c73c400f
sha256: edea88d2ce28d89a9777ea160fbe41a12e50158a6f9c17511491c5293f1e3788
sha512: 2969b7c81eebaa50d4fc576e4e4c0e0515c414b9076d30b6fa9bf443bf5c6dcabba8f7feb8fa22c51c8eb929d2234c43b1af005b4465148cad739e7c40d4fe88
ssdeep: 3072:aRJGrca37JjJ9yQqB1ddOBBRLmLMkMK8vWq13uc3dpPNjg3DWZ:aRJH875J9yxB1dsB6SQq13uapPNjg3E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1316417607E6094C0F26DF2768FA8EABA0756BCD614A101DD29E4BF177F781A3CD31825
sha3_384: 416e4b07a92227827beb9d0a5c074405f5c27a09a833ffd5c2704ee0ddc518cb21ee07ff93139d6f01d0aeeb9eae132d
ep_bytes: 558bec83c4f0b884440010e848efffff
timestamp: 2008-04-22 12:40:36

Version Info:

0: [No Data]

Malware.AI.2220025972 also known as:

LionicTrojan.Win32.Buzus.lD44
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Delf.Inject.Z
ClamAVWin.Trojan.Agent-64491
FireEyeGeneric.mg.473a738146ed6001
McAfeeArtemis!473A738146ED
CylanceUnsafe
K7AntiVirusTrojan ( 7000000f1 )
AlibabaVirTool:Win32/DelfInject.c4fc38ba
K7GWTrojan ( 7000000f1 )
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BCX
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Delf.Inject.Z
NANO-AntivirusTrojan.Win32.Buzus.crpbhl
AvastWin32:Buzus-OZ [Trj]
TencentWin32.Trojan.Generic.Ewnw
Ad-AwareTrojan.Delf.Inject.Z
SophosML/PE-A
ComodoBackdoor.Win32.Poison.~SAG@x3tu
DrWebTrojan.MulDrop.27571
VIPRETrojan.Delf.Inject.Z
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Delf.Inject.Z (B)
GDataTrojan.Delf.Inject.Z
JiangminTrojan/Buzus.blpp
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.AA
ViRobotTrojan.Win32.Buzus.167936.B
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Backdoor/Win32.Rbot.C11461
VBA32BScope.Binder.Buzus.er
ALYacTrojan.Delf.Inject.Z
MAXmalware (ai score=86)
MalwarebytesMalware.AI.2220025972
RisingMalware.Undefined!8.C (TFE:5:pq3eYJJ2nBG)
YandexTrojan.GenAsa!VpQpwd1jMCU
IkarusTrojan.Delf.Inject
FortinetW32/Dropper.DZV!tr
BitDefenderThetaAI:Packer.3BBF55C11B
AVGWin32:Buzus-OZ [Trj]
Cybereasonmalicious.146ed6
PandaTrj/CI.A

How to remove Malware.AI.2220025972?

Malware.AI.2220025972 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment