Malware

About “Malware.AI.2113491292” infection

Malware Removal

The Malware.AI.2113491292 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2113491292 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.2113491292?


File Info:

name: C3C7036130392D6CDF93.mlw
path: /opt/CAPEv2/storage/binaries/85cf3b1e9c6600b006fd8fe0c38e44668234f15b6b386cab7dfdae2a57b14ddb
crc32: 3C108AC1
md5: c3c7036130392d6cdf93f676413951ce
sha1: 7de31b54aa8da6adb5f1e5845980585e713bc53b
sha256: 85cf3b1e9c6600b006fd8fe0c38e44668234f15b6b386cab7dfdae2a57b14ddb
sha512: f5be6bb75130d97ce58583a4289406a990dbaac978919cb6267264d126a8c6caefa301fb1cfc81104569457f49b30ca75cb3065febba531de95d0953b91639ac
ssdeep: 6144:RL7tcnaym0vCFJbv16CX4rMZbagEanzcjj+eg/sc7wSkbPt5FhbYtrlG:RLWjTv+Jd4ra/EaCWsc7bkbLFhEtQ
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T14EA4CF52BFD037C8C4B9123B5655AB04E2EBA6A15B6486C76C106B3E3DB3FE48C3516C
sha3_384: fa58ebd9ef61bb00d026f1e8c2ebe16504b5a1f361b5b6a4596a3d3e44c728db298e4ebbaff5ee67bba2a46b3484c071
ep_bytes: 455357455541bb60000000654b8b3b52
timestamp: 2009-09-26 01:28:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Application Layer Gateway Service
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: ALG.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: ALG.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Malware.AI.2113491292 also known as:

LionicVirus.Win64.Expiro.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.c3c7036130392d6c
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaVirus:Win64/Expiro.bb061d54
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW64/Expiro.AO.gen!Eldorado
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win64/Expiro.CO
APEXMalicious
AvastWin64:Xpirat [Inf]
KasperskyVirus.Win64.Expiro.rd
BitDefenderWin64.Expiro.Gen.6
NANO-AntivirusVirus.Win64.Expiro.clnvwd
MicroWorld-eScanWin64.Expiro.Gen.6
TencentWin64.Virus.Expiro.Szbj
Ad-AwareWin64.Expiro.Gen.6
EmsisoftWin64.Expiro.Gen.6 (B)
TrendMicroVirus.Win64.EXPIRO.MR
McAfee-GW-EditionBehavesLike.Win64.Virus.gc
SophosMal/Generic-S
Paloaltogeneric.ml
GDataWin64.Expiro.Gen.6
JiangminTrojan.Scar.tsz
AviraTR/Patched.Gen
Antiy-AVLTrojan/Generic.ASMalwS.32DE6D
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Raccoon.EC!MTB
Acronissuspicious
ALYacWin64.Expiro.Gen.6
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2113491292
TrendMicro-HouseCallVirus.Win64.EXPIRO.MR
SentinelOneStatic AI – Malicious PE
FortinetW64/Expiro.CE
AVGWin64:Xpirat [Inf]
Cybereasonmalicious.130392

How to remove Malware.AI.2113491292?

Malware.AI.2113491292 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment