Malware

About “Malware.AI.2669549299” infection

Malware Removal

The Malware.AI.2669549299 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2669549299 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Malware.AI.2669549299?


File Info:

name: B97B1B34BE9312A78B07.mlw
path: /opt/CAPEv2/storage/binaries/ac006d3495bfbe62c211b854c7e221d78974ee7f3414ed27da53bab1230dcc65
crc32: 6C7B9FEF
md5: b97b1b34be9312a78b07985ca79be180
sha1: b110aad522ad9dfee3a4d2702bf3241583e57830
sha256: ac006d3495bfbe62c211b854c7e221d78974ee7f3414ed27da53bab1230dcc65
sha512: 0aabf174c71787ad4dcd2257131b1c95faccb971bf04ae95de9b5193fbafacd8d69ca287748234fe4a74f89c9adc215e924c823d8f71ceb1a6b7756589aae875
ssdeep: 24576:JxVNn0hEe41DUR1D1L+4Xb07K4pkW25Tk:neMDUXj2Zkh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11175DE243CE91CA5613EDF7E4AEC329D856EF723B7029C8900D8534506DA709B98BDF9
sha3_384: ce1fc3b487f573c24715ac1c2c315e88272fafe0034f249a81d00656a9a15713dffff235179a6f3eabff4f66a55ccbef
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-10-01 01:22:57

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft Host
FileDescription: Microsoft Windows Host
FileVersion: 4.71.0.0
InternalName: BUTS.exe
LegalCopyright: Copyright © 2016
OriginalFilename: BUTS.exe
ProductVersion: 4.71.0.0
Assembly Version: 4.71.0.0

Malware.AI.2669549299 also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 100)
ALYacIL:Trojan.MSILZilla.5252
MalwarebytesMalware.AI.2669549299
VIPREIL:Trojan.MSILZilla.5252
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004e0f441 )
K7GWTrojan ( 004e0f441 )
Cybereasonmalicious.4be931
CyrenW32/MSIL_Kryptik.DUH.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.AQJ
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderIL:Trojan.MSILZilla.5252
MicroWorld-eScanIL:Trojan.MSILZilla.5252
AvastWin32:RATX-gen [Trj]
Ad-AwareIL:Trojan.MSILZilla.5252
EmsisoftIL:Trojan.MSILZilla.5252 (B)
F-SecureHeuristic.HEUR/AGEN.1235348
McAfee-GW-EditionGenericRXCL-OE!B97B1B34BE93
FireEyeGeneric.mg.b97b1b34be9312a7
SophosML/PE-A + Mal/Mdrop-LY
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.arxk
AviraHEUR/AGEN.1235348
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitIL:Trojan.MSILZilla.D1484
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataIL:Trojan.MSILZilla.5252
GoogleDetected
AhnLab-V3Backdoor/Win32.Fynloski.C1754659
Acronissuspicious
McAfeeGenericRXCL-OE!B97B1B34BE93
MAXmalware (ai score=85)
CylanceUnsafe
RisingTrojan.Dynamer!8.3A0 (TFE:C:emOwIWFp9ZN)
IkarusTrojan-Dropper.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.OPA!tr
BitDefenderThetaGen:NN.ZemsilF.34698.Jn0@aSozg0d
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.2669549299?

Malware.AI.2669549299 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment