Malware

What is “Malware.AI.114492917”?

Malware Removal

The Malware.AI.114492917 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.114492917 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.114492917?


File Info:

name: 780E05C07B2BFED27D5C.mlw
path: /opt/CAPEv2/storage/binaries/fe21754a23bfff30776bc09f9824c3bdeae0378b851cd09d85eef9dfeaa9fd87
crc32: A41D8281
md5: 780e05c07b2bfed27d5ceaaf511b1b8f
sha1: 0926d3fd86981c34db9f0b0381927ca9a7605c64
sha256: fe21754a23bfff30776bc09f9824c3bdeae0378b851cd09d85eef9dfeaa9fd87
sha512: bcd81c7c5a71127a7c75766f87eb65b4b2fe519b8b42d6190aa83a6fa3e10a2acf35e136fa1c6cce93d1907206f60f85e318de3e3e1040707f6de8e17e9aaf49
ssdeep: 12288:hjHRq9C4ajRp4QtbkSlkkix/hcmeO9ZCSLTNQSKqDsIZTHNZm9:hjxPp/4Hqkk62mvKSLmasIZhk9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19375020276D889B6EFBB01718F64B21593EEF8614F105ADFAB06529E197C6C60C343DB
sha3_384: 53543acae0967eb450844a22a2e1dda9660ade39db2bccc3002aa28b46ee13254e54e093c8ace9df7be3d8ed7561bc5a
ep_bytes: e8cbe91800e978feffff558bec6a00ff
timestamp: 2021-02-15 03:11:27

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Eula display
FileVersion: 21.1.20138.422477
InternalName: Eula.exe
LegalCopyright: Copyright 2010-2021 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: Eula.exe
ProductName: EULA
ProductVersion: 21.1.20138.422477
Translation: 0x0409 0x04e4

Malware.AI.114492917 also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Moiva.n!c
AVGWin32:FileInfector-C [Heur]
MicroWorld-eScanWin32.Expiro.Gen.7
FireEyeGeneric.mg.780e05c07b2bfed2
CAT-QuickHealW32.Expiro.R3
MalwarebytesMalware.AI.114492917
SangforVirus.Win32.Expiro.Vqtk
K7AntiVirusVirus ( 005a8b911 )
AlibabaVirus:Win32/Moiva.4aeb68c4
K7GWVirus ( 005a8b911 )
CyrenW32/Expiro.AU.gen!Eldorado
SymantecW32.Xpiro.J!dam
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.NDP
CynetMalicious (score: 100)
APEXMalicious
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:FileInfector-C [Heur]
TencentVirus.Win32.VirMoiva.a
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
DrWebWin32.Expiro.158
VIPREWin32.Expiro.Gen.7
TrendMicroVirus.Win32.EXPIRO.JMA
McAfee-GW-EditionBehavesLike.Win32.Dropper.tt
Trapminemalicious.high.ml.score
SophosW32/Moiva-C
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
AviraW32/Infector.Gen
MAXmalware (ai score=84)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftVirus:Win32/Expiro.NDP!MTB
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2164
VBA32Trojan.Sabsik.TE
ALYacWin32.Expiro.Gen.7
TACHYONVirus/W32.Movia
Cylanceunsafe
PandaW32/Moyv.A
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.114492917?

Malware.AI.114492917 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment