Malware

Should I remove “Malware.AI.1721585494”?

Malware Removal

The Malware.AI.1721585494 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1721585494 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1721585494?


File Info:

name: 44044DAB4A1BB30D0F08.mlw
path: /opt/CAPEv2/storage/binaries/6af1eaad22d3d3add698c49688cb6a9ab993a299a1749ca4bafd7c6ecfd5099c
crc32: B7288FAF
md5: 44044dab4a1bb30d0f080234719b564f
sha1: d72b55a88e7599738ded7165b84191b8d25ab128
sha256: 6af1eaad22d3d3add698c49688cb6a9ab993a299a1749ca4bafd7c6ecfd5099c
sha512: 65e9cbc81648420bed0809d552a048076320482f52f2787971a7d6b0e9dca62d9d42d941f3364a5c5a46c3fa6f2ddaea14a6b39bc163ca71055b04a8f834d937
ssdeep: 12288:vXX0AKEPCkfy6AF14EKy+Odk76dGfFG3j9pjXsx931jAAWLxlp:/X0nEKkfy6AVk7CGfI3jrGVVWd
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T13ED48E01AF4DEBCDF84289343BE6AA44ACF1256B6C8C6107F953F90470747C5E61E6AB
sha3_384: 12260e19bdac359e03691f2325e7eac6928cf6e6faf8f4cdca0b487d1b74c5d73e8636d678416c8ca5b885278cde6fde
ep_bytes: 90554889e55648ffce57415441554156
timestamp: 2008-11-08 16:22:40

Version Info:

CompanyName: Microsoft Corporation
FileDescription: SNMP Trap
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: snmptrap.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: snmptrap.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Malware.AI.1721585494 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin64.Expiro.Gen.3
ALYacWin64.Expiro.Gen.3
CylanceUnsafe
ZillyaVirus.Expiro.Win64.34
K7AntiVirusVirus ( 0040f8071 )
K7GWVirus ( 0040f8071 )
Cybereasonmalicious.b4a1bb
BaiduWin64.Virus.Expiro.r
CyrenW64/Expiro.D!gen
SymantecW64.Xpiro.F
ESET-NOD32Win64/Expiro.AG
APEXMalicious
KasperskyVirus.Win64.Expiro.g
BitDefenderWin64.Expiro.Gen.3
NANO-AntivirusVirus.Win64.Expiro.dtfhve
AvastWin32:Expiro-DD
TencentVirus.Win64.Expiro.ad
Ad-AwareWin64.Expiro.Gen.3
SophosML/PE-A + W64/Expiro-S
DrWebWin64.Expiro.108
VIPREVirus.Win64.Expiro.gen.a (v)
TrendMicroPE64_EXPIRO.AR
McAfee-GW-EditionBehavesLike.Win64.Expiro.hc
FireEyeGeneric.mg.44044dab4a1bb30d
EmsisoftWin64.Expiro.Gen.3 (B)
IkarusVirus.Win32.Expiro
GDataWin64.Expiro.Gen.3
AviraW64/Expiro.AF
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASVirus.311
ArcabitWin64.Expiro.Gen.3
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win64/Expiro2.Gen
Acronissuspicious
McAfeeW64/Expiro.a
TACHYONVirus/W64.Expiro.C
MalwarebytesMalware.AI.1721585494
TrendMicro-HouseCallPE64_EXPIRO.AR
RisingVirus.Expiro!1.A140 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW64/Expiro.Q
AVGWin32:Expiro-DD
PandaW32/Expiro.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecurevirus.win64.expiro.gen

How to remove Malware.AI.1721585494?

Malware.AI.1721585494 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment