Malware

Malware.AI.2227038027 removal

Malware Removal

The Malware.AI.2227038027 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2227038027 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to identify installed analysis tools by registry key
  • Detects VirtualBox through the presence of a registry key
  • Emumerates physical drives
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2227038027?


File Info:

name: C94FE60784E40770D536.mlw
path: /opt/CAPEv2/storage/binaries/302104cdde164565e1353e57a0c00c6ce5be448845c8e6b915cae939aa037f1d
crc32: 48521CCD
md5: c94fe60784e40770d536aa7fb20f58c8
sha1: 1107c9b196fe5ca9a387e066a0f9273fa8a84069
sha256: 302104cdde164565e1353e57a0c00c6ce5be448845c8e6b915cae939aa037f1d
sha512: 7f6f6075b796ad2250ef857cf33672180085915a52c44722f8008af655a3a1731e500ed469f93417dac802db0ddb9cad884236b279e051b72c4d28c4219d9ac7
ssdeep: 24576:q+c39XLVUxGbryMiM0DhVPb2hVDOQp6JMBtBxVH+8w:q+ctXBGGPyP/VPKvKQK8K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1980523AE4E630423C254CC73934982D487FFAC177AE3796BC741660A10B55886BF76FA
sha3_384: a30523ea91b900b2113bb4f12b7e5191fd1ed6f05c0f984df6e10e57b5fe854edc0d4329002ac0b7be0b9f365d3d0932
ep_bytes: 558bec6aff68c8494000684635400064
timestamp: 2014-04-14 01:34:28

Version Info:

0: [No Data]

Malware.AI.2227038027 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.tpzd
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.283
MicroWorld-eScanTrojan.GenericKDZ.25036
FireEyeGeneric.mg.c94fe60784e40770
CAT-QuickHealTrojanPWS.Zbot.AP4
ALYacTrojan.GenericKDZ.25036
MalwarebytesMalware.AI.2227038027
ZillyaBackdoor.Simda.Win32.1295
SangforTrojan.Win32.Injector.Vqyv
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:Win32/Injector.c473b602
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.784e40
BitDefenderThetaGen:NN.ZexaF.36196.1qZ@aOGIvNfb
VirITTrojan.Win32.Generic.CBOP
CyrenW32/A-4d6fc207!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.BBLW
ZonerTrojan.Win32.22648
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.25036
NANO-AntivirusTrojan.Win32.Simda.cwmave
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:Injector-BRO [Trj]
TencentMalware.Win32.Gencirc.10b9bb12
SophosMal/Zbot-QT
F-SecureTrojan.TR/Injector.akrz
BaiduWin32.Trojan.Inject.aj
VIPRETrojan.GenericKDZ.25036
TrendMicroTROJ_MALKRYP.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.25036 (B)
GDataTrojan.GenericKDZ.25036
JiangminTrojan/Generic.azpbf
AviraTR/Injector.akrz
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Injector.BBSG@59nene
ArcabitTrojan.Generic.D61CC
ViRobotTrojan.Win32.Zbot.79720.A
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Simda
GoogleDetected
AhnLab-V3Trojan/Win32.Ransomlock.R104895
McAfeeDownloader-FYH!C94FE60784E4
TACHYONBackdoor/W32.Simda.871272
VBA32BScope.Malware-Cryptor.Hlux
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_MALKRYP.SM1
RisingBackdoor.Simda!8.2D9 (CLOUD)
YandexTrojan.Injector!QR1+LqOvJfQ
IkarusBackdoor.Win32.Simda
FortinetW32/ZBOT.QU!tr
AVGWin32:Injector-BRO [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.2227038027?

Malware.AI.2227038027 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment