Malware

About “Malware.AI.2224512912” infection

Malware Removal

The Malware.AI.2224512912 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2224512912 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.2224512912?


File Info:

name: 9C46B34F8B60866CFB79.mlw
path: /opt/CAPEv2/storage/binaries/60922e0769ec8a51da1f7a5048636e2e4afd9c7aaf02e350464f43fb8ce1947f
crc32: 8B42354E
md5: 9c46b34f8b60866cfb7976c22cf2b60e
sha1: 68c9a0dfea80bc0c1de3b9c977e5640bfa741bcd
sha256: 60922e0769ec8a51da1f7a5048636e2e4afd9c7aaf02e350464f43fb8ce1947f
sha512: f7cd848ae95e5a33a28d0cd82a1919b09fa716e5f88f7b6f110c6d1caf66d04671a8be4c1b6a732b75bbef47fe092abed221fd50f16a80f2d3a41a52f6483526
ssdeep: 12288:bpupVnGlnNvMgcPz56Xz9iQKEPbIOHCfT18E6hnrycfO:bsfGdNdcr5iz9d9bIOoTWRtycfO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AD4239EBAE134B2F854693A8E64353B66FE7D302D6468135B90CF1A93F5280633C747
sha3_384: bdf88e765876bd3f906140aeef31b09673996d2202997557c1157843e1efb08ec2876ba869aabefa1d04269512a0aa8b
ep_bytes: 558bec81ec40040000e8a40d0000e8a2
timestamp: 2008-11-17 08:34:30

Version Info:

0: [No Data]

Malware.AI.2224512912 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.UserStartup.KqZ@aKd!JEi
ClamAVWin.Spyware.Zbot-9841872-0
FireEyeGeneric.mg.9c46b34f8b60866c
ALYacGen:Trojan.UserStartup.KqZ@aKd!JEi
CylanceUnsafe
VIPREGen:Trojan.UserStartup.KqZ@aKd!JEi
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004dceae1 )
K7GWSpyware ( 004dceae1 )
Cybereasonmalicious.f8b608
CyrenW32/Agent.CC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Zbot.ACH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.UserStartup.KqZ@aKd!JEi
NANO-AntivirusTrojan.Win32.Panda.ifgd
AvastSf:Zbot-CQ [Trj]
Ad-AwareGen:Trojan.UserStartup.KqZ@aKd!JEi
SophosML/PE-A + Troj/Zbot-HJ
ComodoTrojWare.Win32.TrojanSpy.Zbot.Gen@11evrg
DrWebTrojan.PWS.Panda.122
ZillyaTrojan.Zbot.Win32.8552
TrendMicroTSPY_ZBOT.SMRL
McAfee-GW-EditionPWS-Zbot.gen.ajl
Trapminesuspicious.low.ml.score
EmsisoftGen:Trojan.UserStartup.KqZ@aKd!JEi (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.UserStartup.KqZ@aKd!JEi
JiangminTrojanSpy.Zbot.aida
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.31
ArcabitTrojan.UserStartup.EB1AAF
MicrosoftPWS:Win32/Zbot.gen!R
GoogleDetected
AhnLab-V3Win-Trojan/Zbot.Gen
Acronissuspicious
McAfeePWS-Zbot.gen.ajl
VBA32SScope.Trojan.Bofa
MalwarebytesMalware.AI.2224512912
TrendMicro-HouseCallTSPY_ZBOT.SMRL
RisingTrojan.Generic@AI.100 (RDML:i5NHR+am3DcBVkBexdt6Kw)
IkarusPWS.Win32
FortinetW32/Zbot.BCW!tr.bdr
BitDefenderThetaAI:Packer.3F2925C31E
AVGSf:Zbot-CQ [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.2224512912?

Malware.AI.2224512912 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment