Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

PUA:Win32/Maltiverza removal tips

Published Apr 26, 2024 PUA category 3 min read
Report context

What to verify before removal

This pua entry is most useful when PUA:Win32/Maltiverza removal tips appears after a software bundle, browser extension install, or unwanted system utility. Treat it as moderate risk until you confirm whether the alert is tied to browser settings, scheduled tasks, or a persistent updater.

Start by comparing the local file name with 9F34A75AA4CD9B5719AC.mlw, then review the behavior notes for bundled installers, browser policy changes, notification abuse, and unwanted startup entries. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
9F34A75AA4CD9B5719AC.mlw
  • Compare the suspicious file name with 9F34A75AA4CD9B5719AC.mlw.
  • Confirm the detection name matches PUA:Win32/Maltiverza removal tips before removing related files.
  • Review the report for bundled installers, browser policy changes, notification abuse, and unwanted startup entries so the cleanup is based on observed behavior, not only the label.
  • Remove the unwanted app, reset affected browser settings, and check extensions before reconnecting accounts.

The PUA:Win32/Maltiverza is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What PUA:Win32/Maltiverza virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine PUA:Win32/Maltiverza?


File Info:

name: 9F34A75AA4CD9B5719AC.mlw
path: /opt/CAPEv2/storage/binaries/66e358e3c2f5c3abeefb793cee81630f947ffa32b5cc1a5310082b33dfaf6615
crc32: E3013B08
md5: 9f34a75aa4cd9b5719aca6bd6f23e8a1
sha1: 11fcbdd247c7701e7bcbe304710aaf83290841f1
sha256: 66e358e3c2f5c3abeefb793cee81630f947ffa32b5cc1a5310082b33dfaf6615
sha512: 5f5df8ef7ed8b5d48f16f5beac0110c2ffa516a212cbd65bb3bc8ff1812edcb33739df4e74e53dd0bd12d38ed42d52a2c5d65ba66038fcb55c16b469d1d16143
ssdeep: 12288:JqswXAPBAuxlVtD751epIOJMJf49/ThWH0Mx:4swXAPBAuxlVtD11eIOJMJ+gH0Mx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB05C0317D90C03FC2510C316E6CA7B592FEDDE666E6580BB380BB9D5A70EC09636627
sha3_384: 0eda760d6f41c8df91d6d350823d71c74a1240570fd7ab54598d956bae4e0a2a9b19834e71e94b6791461558814418cb
ep_bytes: 6a606878864500e88de1ffffbf940000
timestamp: 2009-07-13 09:26:19

Version Info:

FileDescription: Zylom Games
FileVersion: 1, 0, 0, 1
InternalName: Zylom Games
LegalCopyright: Copyright (C) 2004
OriginalFilename: Zylom Games
ProductName: Zylom Games
ProductVersion: 1, 0, 0, 1
Translation: 0x0413 0x04b0

PUA:Win32/Maltiverza also known as:

Bkav W32.AIDetectMalware
AVG Win32:Evo-gen [Trj]
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.71714432
CAT-QuickHeal PUA.Downloader.S105101
Skyhigh BehavesLike.Win32.Generic.bh
McAfee Artemis!9F34A75AA4CD
Malwarebytes Generic.Malware.AI.DDS
Zillya Downloader.Agent.Win32.79729
Sangfor Suspicious.Win32.Save.ins
Alibaba Trojan:Win32/Zylom.468f34eb
K7GW Hacktool ( 700007861 )
VirIT Trojan.Win32.DownLoad2.BYQU
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Generik.LACFGUB
Cynet Malicious (score: 100)
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Trojan.GenericKD.71714432
NANO-Antivirus Trojan.Win32.Gendal.iebvj
SUPERAntiSpyware PUP.Downloader/Variant
Avast Win32:Evo-gen [Trj]
Tencent Win32.Trojan.Generic.Sgil
Emsisoft Application.Downloader (A)
DrWeb Trojan.DownLoad2.34236
VIPRE Trojan.GenericKD.71714432
TrendMicro TROJ_GEN.R002C0GBK24
Trapmine malicious.high.ml.score
FireEye Generic.mg.9f34a75aa4cd9b57
Sophos Mal/Generic-S
SentinelOne Static AI – Suspicious PE
Jiangmin TrojanDownloader.Agent.cgry
Webroot W32.Malware.gen
Varist W32/Zylom.A.gen!Eldorado
Avira GAME/Zylom.Gen5
Antiy-AVL Worm/Win32.Dloader.a
Kingsoft malware.kb.a.1000
Microsoft PUA:Win32/Maltiverza
Arcabit Trojan.Generic.D4464680
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Trojan.GenericKD.71714432
Google Detected
VBA32 BScope.TrojanDownloader.Agent
ALYac Trojan.GenericKD.71714432
MAX malware (ai score=100)
Cylance unsafe
Panda Trj/CI.A
TrendMicro-HouseCall TROJ_GEN.R002C0GBK24
Rising Downloader.Zylom!1.68C7 (CLASSIC)
Ikarus Trojan.Win32.Agent
MaxSecure Trojan.Malware.1461899.susgen
Fortinet W32/Generic.AC.2101081
DeepInstinct MALICIOUS
alibabacloud Suspicious

How to remove PUA:Win32/Maltiverza?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.