Malware

Malware.AI.3333097730 removal guide

Malware Removal

The Malware.AI.3333097730 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3333097730 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.3333097730?


File Info:

name: DFF9BEFDB593DA8CEC40.mlw
path: /opt/CAPEv2/storage/binaries/2d243b10107a1e748bc84a2c4a11ccaee94daa98b0f7c9f86902c911b5121ef5
crc32: D4E2B1A3
md5: dff9befdb593da8cec40589f0f39225c
sha1: eeafe70708558b41285a3a3fd6d8caab938519dd
sha256: 2d243b10107a1e748bc84a2c4a11ccaee94daa98b0f7c9f86902c911b5121ef5
sha512: b4dd8b9dc86efbaff0cf5657992403f05c950df0b0e0f2805eb80a808245f148ae3c16d5243768df0f99e37b274745378e35b2c147412a011d4248e186be2d22
ssdeep: 6144:PrMyKsy21PfI7wqIwD3Cn9/VEx4yKBsETYFBWcSAsVb0jGPt7Rk8BAK5QCm/3lTO:PrMyKsyLb+n9dEeyKGETHbsGv55LsO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166948D74E62574CCCC2F9FF839D9B890B994E750321AE4529CEF5B4D02ACB6B8364943
sha3_384: 29ada5970280710efadab5c6b482861b56a3047a6e19db942b1fb8eb2cb96f60818d2f4842dd46c55bbc93f595151242
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2009-08-08 17:58:07

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Services
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: svchost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: svchost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Malware.AI.3333097730 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.dff9befdb593da8c
CrowdStrikewin/malicious_confidence_90% (W)
VirITWin32.Expiro.CV
CyrenW32/Expiro.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDG
APEXMalicious
ClamAVWin.Virus.Expiro-9916846-0
NANO-AntivirusVirus.Win32.Gen.ccmw
TencentVirus.Win32.Expiro.ns
Ad-AwareWin32.Expiro.Gen.6
SophosML/PE-A + Mal/EncPk-MK
DrWebWin32.Expiro.150
McAfee-GW-EditionBehavesLike.Win32.Expiro.gc
EmsisoftWin32.Expiro.Gen.6 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Stealer.abj
AviraTR/Patched.Gen
MAXmalware (ai score=83)
SUPERAntiSpywareTrojan.Agent/Gen-Injector
GDataWin32.Expiro.Gen.6
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacWin32.Expiro.Gen.6
MalwarebytesMalware.AI.3333097730
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.db593d

How to remove Malware.AI.3333097730?

Malware.AI.3333097730 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment