Malware

Should I remove “Win32/Amonetize.OT potentially unwanted”?

Malware Removal

The Win32/Amonetize.OT potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Amonetize.OT potentially unwanted virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Amonetize.OT potentially unwanted?


File Info:

name: 9D49B2AC912D8574A96F.mlw
path: /opt/CAPEv2/storage/binaries/b0ba162cfb6f001b6ac4a549235b15398b09787900e784696ed05846b9b6b2e5
crc32: D00B211F
md5: 9d49b2ac912d8574a96f6d66bdeed68a
sha1: 0e0e58ea83769810c06dc2e50a02ff9626e8a472
sha256: b0ba162cfb6f001b6ac4a549235b15398b09787900e784696ed05846b9b6b2e5
sha512: 8c4fed96963a0326c5346b5fb87301e67fe608e7e15ba45f1e8327dbb9c21bc0b0af54304df94abebd9ce0fb89fbe3969efcdaae23acb94d512a0760c595e378
ssdeep: 24576:c9V/rnTXIUqiBmgOuBh0lMx7hv4gGVjl7xzX2KWL/JM8l0Wis:UDsUq6xO0h0lMxtZUfA0Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160353344E045D671C7599D3CC42896FE0DC37D36EA4C23A32D2C3E6EF5BAAB62602716
sha3_384: 04ac2bce44c26941ec194ab6dea57ff822adfca979308ac11fa2db8e0e4d535a8b2e1347991d583ba9cf4c3852b59b61
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2016-02-02 14:17:34

Version Info:

0: [No Data]

Win32/Amonetize.OT potentially unwanted also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
DrWebAdware.Downware.19117
MicroWorld-eScanGen:Application.Imonetize.2
FireEyeGeneric.mg.9d49b2ac912d8574
McAfeeGenericRXMS-EU!9D49B2AC912D
CylanceUnsafe
ZillyaAdware.Amonetize.Win32.60581
SangforSuspicious.Win32.Save.a
K7AntiVirusAdware ( 004db3121 )
K7GWAdware ( 004db3121 )
Cybereasonmalicious.c912d8
BitDefenderThetaGen:NN.ZexaF.34646.cnraaG6GHwii
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Amonetize.OT potentially unwanted
APEXMalicious
ClamAVWin.Packed.Zusy-9837875-0
Kasperskynot-a-virus:VHO:AdWare.Win32.Amonetize.gen
BitDefenderGen:Application.Imonetize.2
NANO-AntivirusTrojan.Win32.Amonetize.jscggc
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Application.Imonetize.2
EmsisoftGen:Application.Imonetize.2 (B)
BaiduWin32.Trojan.Kryptik.aax
VIPREGen:Application.Imonetize.2
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tc
Trapminemalicious.high.ml.score
SophosGeneric PUA AO (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Application.Imonetize.2
JiangminAdWare.Amonetize.hay
GoogleDetected
AviraADWARE/Amonetize.Gen7
MAXmalware (ai score=73)
Antiy-AVLTrojan/Generic.ASMalwS.3125
ArcabitApplication.Imonetize.2
MicrosoftPUADlManager:Win32/Amonetize
CynetMalicious (score: 99)
VBA32Downloader.AdLoad
ALYacGen:Application.Imonetize.2
MalwarebytesMalware.AI.3418682966
TencentMalware.Win32.Gencirc.10c477a5
YandexPUA.Amonetize!hXoBrBKX+SY
IkarusPUA.Amonetize
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Amonetize
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Win32/Amonetize.OT potentially unwanted?

Win32/Amonetize.OT potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment