Malware

Win64/Exploit.CVE-2017-0213.A removal instruction

Malware Removal

The Win64/Exploit.CVE-2017-0213.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Exploit.CVE-2017-0213.A virus can do?

  • Network activity detected but not expressed in API logs

How to determine Win64/Exploit.CVE-2017-0213.A?


File Info:

crc32: A387F4A6
md5: 00b2c6694ef0d47b191cbe0bbffe6d7e
name: 00B2C6694EF0D47B191CBE0BBFFE6D7E.mlw
sha1: 75722e25b8b0a0b5d75dca01b293c32b23bd42ff
sha256: bbb8f27ef93a91cedacf8adf36e2a9e8e9621e97f7207cf12de90090e32cec20
sha512: 3952573fa986773e2e8173e70d21900816e5467ce41beb6f6f3439b1ffed5939fbcb2795adb1f0b008bfd0beaa41715b9bb634bc23ebb44b2d1db537eb5c3fd8
ssdeep: 3072:5cvrKSBuRWy3ALuEG8IFtMH673vxuElWazC9qPldFvsE8iw7c4h:wfgwy3ALtI/G6rvAEl+9qPmEPMc
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: calling an exe from the resource.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: calling an exe from the resource
ProductVersion: 1.0.0.0
FileDescription: calling an exe from the resource
OriginalFilename: calling an exe from the resource.exe

Win64/Exploit.CVE-2017-0213.A also known as:

DrWebExploit.Siggen.1473
MicroWorld-eScanTrojan.GenericKD.45661787
FireEyeGeneric.mg.00b2c6694ef0d47b
McAfeeArtemis!00B2C6694EF0
CylanceUnsafe
AegisLabHacktool.Win32.CVE-2017-0213.3!c
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.45661787
K7GWTrojan ( 005247961 )
K7AntiVirusTrojan ( 005247961 )
BitDefenderThetaGen:NN.ZemsilCO.34804.km0@aSqhBcb
CyrenW32/Trojan.UVLF-2974
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R011C0RB421
AvastWin64:CVE-2017-0213-B [Expl]
ClamAVWin.Exploit.Generic-9828435-0
KasperskyHEUR:Exploit.Win32.CVE-2017-0213.gen
AlibabaExploit:Win64/CVE-2017-0213.3321e1b4
TencentWin32.Trojan.Generic.Eek
Ad-AwareTrojan.GenericKD.45661787
SophosMal/Generic-R
F-SecureExploit.EXP/CVE-2017-0213.gnhpf
TrendMicroTROJ_GEN.R011C0RB421
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.45661787 (B)
IkarusExploit.CVE-2017-0213
AviraEXP/CVE-2017-0213.gnhpf
MicrosoftTrojan:Win32/Ymacco.AABB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2B8BE5B
ZoneAlarmHEUR:Exploit.Win32.CVE-2017-0213.gen
GDataTrojan.GenericKD.45661787
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_CVE-2017-0213.C4323871
VBA32Exploit.CVE-2017-0213
ALYacTrojan.GenericKD.45661787
MAXmalware (ai score=87)
MalwarebytesMalware.AI.4232894115
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32Win64/Exploit.CVE-2017-0213.A
RisingExploit.CVE-2017-0213!8.E88E (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/CVE_2017_0213.A!tr
AVGWin64:CVE-2017-0213-B [Expl]
Cybereasonmalicious.5b8b0a
Qihoo-360Win32/Exploit.Generic.HwMAAbsA

How to remove Win64/Exploit.CVE-2017-0213.A?

Win64/Exploit.CVE-2017-0213.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment