Malware

How to remove “Malware.AI.822224531”?

Malware Removal

The Malware.AI.822224531 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.822224531 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.822224531?


File Info:

name: 3CB206CC7A170BD1B6AC.mlw
path: /opt/CAPEv2/storage/binaries/470b6a5ad2b439e523b4810fa9941a302f2aaba8e3e1b4696a8a4dbdd7c5d52b
crc32: 7CFDBBD7
md5: 3cb206cc7a170bd1b6aca601ee3a1240
sha1: 8a0863e12839a5f6b4206a50be478433b21a057d
sha256: 470b6a5ad2b439e523b4810fa9941a302f2aaba8e3e1b4696a8a4dbdd7c5d52b
sha512: be6365edf49d26e5cd3303e4fa2284e195a19920f76745b14c5191b6314acc22a1c5353be8c8ab62ff895d26d57c60fc65d85dcabb45ac28f13b9f9cd874a662
ssdeep: 3072:rLyH71AELrtebALeBdVw9+TpFLIxI+UH:fyBAGrteda8zI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6B3AD22F7FC8954F6F32B74AA7296900A327CA1ED74866E2220F95F5C75B10C861773
sha3_384: eb98006d680fc97a63ce28c27a7e51677aa6ee766adb4d76bba0c9df0f3eb36d7e59706bc667f8f5cbbcf9f380b59493
ep_bytes: 60be004042008dbe00d0fdff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.822224531 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.ShellHook.gmHfaiN44Dib
ClamAVWin.Trojan.Ag-1
FireEyeGeneric.mg.3cb206cc7a170bd1
McAfeeGenericRXAA-FA!3CB206CC7A17
CylanceUnsafe
ZillyaTrojan.Lmir.Win32.4607
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_90% (D)
BaiduWin32.Trojan-PSW.OLGames.bm
CyrenW32/Trojan.NKWF-7746
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Legendmir.NHY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Antavmu.ammh
BitDefenderGen:Trojan.ShellHook.gmHfaiN44Dib
NANO-AntivirusTrojan.Win32.Lmir.bcuxns
AvastWin32:Malware-gen
TencentTrojan.Win32.Scar.16000123
Ad-AwareGen:Trojan.ShellHook.gmHfaiN44Dib
SophosML/PE-A + Troj/PWS-BUY
ComodoTrojWare.Win32.GameThief.Lmir.kot@2oj58u
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.PWS.Legmir.5401
VIPREGen:Trojan.ShellHook.gmHfaiN44Dib
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Trojan.ShellHook.gmHfaiN44Dib (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ShellHook.gmHfaiN44Dib
JiangminTrojan/PSW.GamePass.dmw
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[GameThief]/Win32.Lmir
ArcabitTrojan.ShellHook.gmHfaiN44Dib
ViRobotTrojan.Win32.A.PSW-Lmir.109172[UPX]
ZoneAlarmTrojan.Win32.Antavmu.ammh
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Lmirhack.C50100
Acronissuspicious
VBA32TrojanPSW.Lmir
ALYacGen:Trojan.ShellHook.gmHfaiN44Dib
MAXmalware (ai score=80)
MalwarebytesMalware.AI.822224531
RisingWorm.Fasong!8.297 (TFE:5:lxXcwuf3sWE)
YandexTrojan.GenAsa!UPFsd2w5ZGI
IkarusTrojan-GameThief.Win32.Lmir
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.FT!tr
BitDefenderThetaAI:Packer.B88C2B9F1D
AVGWin32:Malware-gen
Cybereasonmalicious.c7a170

How to remove Malware.AI.822224531?

Malware.AI.822224531 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment