Malware

Malware.AI.3450330588 removal tips

Malware Removal

The Malware.AI.3450330588 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3450330588 virus can do?

  • Loads a driver
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify a Browser Helper Object
  • Creates a copy of itself

Related domains:

www2.17h.net.cn

How to determine Malware.AI.3450330588?


File Info:

crc32: C66CCF56
md5: 67a26f063122d42228c443bb6dddf24e
name: 67A26F063122D42228C443BB6DDDF24E.mlw
sha1: b6fb4d0bebef9817fb55206ebd22ce4799981317
sha256: 1e51ab8bd68b0828edc4d5c919934eba5cbbd0351c6b7e262ac0f3071345eb1b
sha512: 48ea7f71887927636f6eb0979c73009275caa99eb6221d5b0521d8d28060f74eb3dbdc8bd1cbb8c9a0bef7c001f07c83b6b6362098b01fda5a3d7a7e62cb687e
ssdeep: 768:zg3GL0TkSMhShSI7koKDQhbFWUw3IOlloLYsi9EL:tL0TZpkoVpQVIOILYYL
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2007
InternalName: Microsoft
FileVersion: 8, 2, 5, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft
SpecialBuild:
ProductVersion: 8, 2, 5, 1
FileDescription: Microsoft
OriginalFilename: Microsoft.EXE
Translation: 0x0804 0x04b0

Malware.AI.3450330588 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004bcce41 )
Elasticmalicious (high confidence)
DrWebTrojan.Click2.32990
ClamAVWin.Trojan.Agent-406994
ALYacGen:Trojan.Heur.bq0@ti2x3Cfb
CylanceUnsafe
ZillyaTrojan.Agent.Win32.768219
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaVirTool:Win32/Rootkitdrv.23a69434
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.63122d
CyrenW32/KillAV.AU.gen!Eldorado
SymantecTrojan.KillAV
ESET-NOD32a variant of Win32/TrojanClicker.Agent.NCZ
APEXMalicious
AvastWin32:Pasta [Cryp]
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Agent.qzq
BitDefenderGen:Trojan.Heur.bq0@ti2x3Cfb
NANO-AntivirusVirus.Win32.Agent.dvixmz
MicroWorld-eScanGen:Trojan.Heur.bq0@ti2x3Cfb
TencentMalware.Win32.Gencirc.10bf4ddb
Ad-AwareGen:Trojan.Heur.bq0@ti2x3Cfb
SophosW32/Pidgeon-A
BitDefenderThetaAI:Packer.F48189FC23
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionFlyagent.d
FireEyeGeneric.mg.67a26f063122d422
EmsisoftGen:Trojan.Heur.bq0@ti2x3Cfb (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.caxu
WebrootW32.KillAV.Gen
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_89%
MicrosoftTrojan:Win32/Killav
GDataGen:Trojan.Heur.bq0@ti2x3Cfb
AhnLab-V3Win-Trojan/Malpacked5.Gen
Acronissuspicious
McAfeeFlyagent.d
MAXmalware (ai score=100)
VBA32BScope.Trojan.MulDrop
MalwarebytesMalware.AI.3450330588
PandaTrj/CI.A
RisingPacker.Win32.Agent.g (CLASSIC)
YandexTrojan.GenAsa!AakuNAQlrCQ
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.1355911.susgen
FortinetW32/CoinMiner.BELF!tr
AVGWin32:Pasta [Cryp]
Paloaltogeneric.ml

How to remove Malware.AI.3450330588?

Malware.AI.3450330588 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment