Malware

Malware.AI.522945657 removal guide

Malware Removal

The Malware.AI.522945657 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.522945657 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Malware.AI.522945657?


File Info:

name: 67E3E6DD77408AF9612A.mlw
path: /opt/CAPEv2/storage/binaries/b7fc9ce59ca04c45649bdc6d4d37c2bfc969bfee1bf2c31236ffde0c4283d6ff
crc32: 5A5D6B70
md5: 67e3e6dd77408af9612aeb47553941ef
sha1: b9e775753c7ebedf8dcbb2aba4f47a45d4b04a25
sha256: b7fc9ce59ca04c45649bdc6d4d37c2bfc969bfee1bf2c31236ffde0c4283d6ff
sha512: 894c3e098a52237abf2813b1702b666c433821a58bcae4e646f85f0e2f59fd73e849605c2a8ca62590284cb8215093549cba45addc2dcf714396146753ebc225
ssdeep: 1536:/3AT3lAffMd5qC0XKZWatoZOnC331B46uxzub:K3Cff+5qC4KxkOnCHH4jc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EC938427F918E02BE06A85F06914D95638313D772D949E47A7888B7829B16D37CF0B2F
sha3_384: c63e2bb5a66a2255d928e9f1198fdf54af077b06272c51a86274074f4d54dd1a97c4bfc4d32a19b72723e745322da74d
ep_bytes: 68ac244000e8eeffffff000000000000
timestamp: 2017-01-16 12:53:29

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Royal Boskalis Westminster
ProductName: Windows Viewer
FileVersion: 6.00
ProductVersion: 6.00
InternalName: ijkss
OriginalFilename: ijkss.exe

Malware.AI.522945657 also known as:

MicroWorld-eScanGen:Variant.Johnnie.257244
FireEyeGeneric.mg.67e3e6dd77408af9
McAfeeGenericRXCE-JE!67E3E6DD7740
CylanceUnsafe
ZillyaDownloader.VB.Win32.111647
K7AntiVirusTrojan-Downloader ( 005047831 )
K7GWTrojan-Downloader ( 005047831 )
Cybereasonmalicious.d77408
CyrenW32/Delf.ERFL-3818
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.VB.RBO
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Johnnie.257244
AvastWin32:Malware-gen
RisingDownloader.VB!8.1EB (TFE:5:jTHo9TzJ6mO)
Ad-AwareGen:Variant.Johnnie.257244
EmsisoftGen:Variant.Johnnie.257244 (B)
DrWebTrojan.MulDrop8.55285
VIPREGen:Variant.Johnnie.257244
McAfee-GW-EditionGenericRXCE-JE!67E3E6DD7740
SophosMal/VBCheMan-C
IkarusTrojan-Downloader.Win32.VB
GDataGen:Variant.Johnnie.257244
JiangminTrojan.VB.ywg
AviraHEUR/AGEN.1239408
Antiy-AVLTrojan/Generic.ASMalwS.9E
ArcabitTrojan.Johnnie.D3ECDC
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32TScope.Trojan.VB
ALYacGen:Variant.Johnnie.257244
MAXmalware (ai score=81)
MalwarebytesMalware.AI.522945657
YandexTrojan.GenAsa!OJW8ZwKpcRU
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZevbaF.34646.fm2@aCV6pYki
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Malware.AI.522945657?

Malware.AI.522945657 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment