Malware

Should I remove “Win32/Amonetize.AAH potentially unwanted”?

Malware Removal

The Win32/Amonetize.AAH potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Amonetize.AAH potentially unwanted virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

How to determine Win32/Amonetize.AAH potentially unwanted?


File Info:

name: 6195F83FC075401D4AB6.mlw
path: /opt/CAPEv2/storage/binaries/e52297cc56d5f153c16f4aba6eecaf3112fb7dd5a5aa44a2cbe61b561f3c2f52
crc32: 52316BDF
md5: 6195f83fc075401d4ab6e3f5b9ae0cfd
sha1: 68b6b1602c39e33ec64d8858ee3388a3d0d16d24
sha256: e52297cc56d5f153c16f4aba6eecaf3112fb7dd5a5aa44a2cbe61b561f3c2f52
sha512: de951408ca03a439f49f1c03947575a68f1e0cab3ad634e2c70cc5466f0885521d26a10322dd1db414173f5b3a23ce4ed8117fd3aa8b7335002012eeb6b0a302
ssdeep: 12288:txjBk8U6UfE6zXiECdNxF2IJGSVfJnXWjOrg97G0q98jp0ZMvR2gGpQ:pU6UnbeF5TfpXPgU0IUpFvRnGpQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18405023275B2C573F8620F74957CA4B142DEBD72D75F89D362803E9A39362D04E3826A
sha3_384: b430e3909e2ac2c67ea0e414760ad646560f25e11ff24f87e6a9cdba7884f08edb51689637ee753bf3caad6ec983ff4d
ep_bytes: e827190000e95efeffff558becff1520
timestamp: 2016-01-06 06:19:23

Version Info:

FileVersion: 1.0.0.1
InternalName: inst.exe
LegalCopyright: Copyright (C) 2015
OriginalFilename: inst.exe
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Win32/Amonetize.AAH potentially unwanted also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.AdLoad.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Application.Imonetize.2
FireEyeGeneric.mg.6195f83fc075401d
CAT-QuickHealTrojan.Generic.100101
McAfeePUP-RHRM
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 005878b11 )
K7GWUnwanted-Program ( 005878b11 )
Cybereasonmalicious.fc0754
CyrenW32/Downloader.QM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Amonetize.AAH potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Zusy-9837875-0
Kasperskynot-a-virus:UDS:AdWare.Win32.Amonetize.sb
BitDefenderGen:Application.Imonetize.2
SUPERAntiSpywarePUP.Amonetize/Variant
AvastWin32:Adware-gen [Adw]
RisingTrojan.Generic@ML.94 (RDML:3y9binK6IBtq+6+3AZeEAA)
Ad-AwareGen:Application.Imonetize.2
EmsisoftGen:Application.Imonetize.2 (B)
ComodoApplication.Win32.Amonetize.NX@682i40
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPUP-RHRM
SophosGeneric PUA GI (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Application.Imonetize.2
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1672BC9
MicrosoftPUADlManager:Win32/Amonetize
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Imonetize.R175109
Acronissuspicious
ALYacGen:Application.Imonetize.2
MAXmalware (ai score=72)
VBA32BScope.Trojan.Amonetize
MalwarebytesPUP.Optional.Amonetize
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.GenAsa!tNBqp70OvEk
eGambitUnsafe.AI_Score_100%
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Amonetize.AAH potentially unwanted?

Win32/Amonetize.AAH potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment