Malware

Malware.AI.222112395 removal

Malware Removal

The Malware.AI.222112395 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.222112395 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.222112395?


File Info:

name: B38B4F694A2B0441549A.mlw
path: /opt/CAPEv2/storage/binaries/87ee5f915604b49e64fe808889ecd645392482e0107e80928053790105c27c9a
crc32: 2EFA7636
md5: b38b4f694a2b0441549ae8b66ece03ee
sha1: 3c74d1e7f00c839fe3437b76170f5aa2ac36af30
sha256: 87ee5f915604b49e64fe808889ecd645392482e0107e80928053790105c27c9a
sha512: 89d104f09cb8fd678dbf85bf8bbc16c4282ef23cdcd4611ac0459c0ca35b758f792b05ab175680c102b35038e95d86148b83161702ff82354e7631338de1d8d3
ssdeep: 1536:sm0D+h7JiBvgGeRT9ZSdNoRJHcN0XXLdtY4XSb1F1ZJH+8f0LyZnCl/lVkx8le6v:oD+JYBIzT9ZwNoRJHceX7rY4C5FSyZn8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B693011FF7E098E7E4C35A7119B76B35FB7B421658336A870B500F6A3E248825A2D3D4
sha3_384: 37932d492ad5a817a449522092abf3b2cefe712d87255343382526be2d96eeb62d8d15d609966f563b15add457696d3a
ep_bytes: 83ec1053555657c7442414f091400033
timestamp: 2003-11-19 13:13:54

Version Info:

0: [No Data]

Malware.AI.222112395 also known as:

LionicAdware.Win32.MBKWBar.2!c
DrWebAdware.Siggen.209
MicroWorld-eScanDropped:Application.Mbkw.BAR
FireEyeDropped:Application.Mbkw.BAR
ALYacDropped:Application.Mbkw.BAR
MalwarebytesMalware.AI.222112395
SangforTrojan.Win32.Mbkw.BAR
K7AntiVirusRiskware ( 0040eff71 )
AlibabaAdWare:Win32/MBKWBar.e9d1320a
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZedlaF.34062.hu4@aKXlAEpk
CyrenW32/Adware.GVSD-7971
SymantecAdware.MBKWbar
TrendMicro-HouseCallADW_MBKWBAR.A
Kasperskynot-a-virus:AdWare.Win32.MBKWBar.a
BitDefenderDropped:Application.Mbkw.BAR
NANO-AntivirusTrojan.Win32.TrjGen.qoasw
AvastWin32:Adware-gen [Adw]
TencentWin32.Adware.Mbkwbar.Pepn
Ad-AwareDropped:Application.Mbkw.BAR
EmsisoftDropped:Application.Mbkw.BAR (B)
ComodoMalware@#1qs471wp4zvbh
VIPREMBKWBar
TrendMicroADW_MBKWBAR.A
McAfee-GW-EditionAdware-MBKWBar.a.dr
SophosMBKWBar-Installer (PUA)
GDataDropped:Application.Mbkw.BAR
JiangminAdWare.MBKWBar.a
WebrootAdware.IeToolbar
AviraTR/Drop.Toolbar.M.A
Antiy-AVLTrojan/Generic.ASMalwS.B5F1
KingsoftWin32.Troj.MBKWBar.a.(kcloud)
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.AB
CynetMalicious (score: 99)
McAfeeAdware-MBKWBar.a.dr
MAXmalware (ai score=76)
VBA32AdWare.MBKWBar
CylanceUnsafe
APEXMalicious
YandexAdware.MBKWBar!pXzPXWRvSlM
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.Adware
FortinetAdware/Win32_MBKWBar
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.94a2b0
PandaGeneric Malware
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.222112395?

Malware.AI.222112395 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment