Malware

Malware.AI.2488916850 removal guide

Malware Removal

The Malware.AI.2488916850 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2488916850 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.2488916850?


File Info:

name: 14EFDC48F7E52697E5ED.mlw
path: /opt/CAPEv2/storage/binaries/d46272b8077b46782d4c2a5a2a1a9415adf959b7c927d9db9c2933033e720a32
crc32: 7902D228
md5: 14efdc48f7e52697e5ed799a2cee13c0
sha1: 664a9ff13950c21743282d30d8381c5c43c65b8c
sha256: d46272b8077b46782d4c2a5a2a1a9415adf959b7c927d9db9c2933033e720a32
sha512: d25d1b6ba72bb1030f9a4a72e1120965930c8a5f08dc31859273fcea4b005386fbbcbdf0eb0da804fc24887689eebccb82ede17646acbb9438c3f8172159ff00
ssdeep: 12288:vaqzPTY53of4XgbXZqHfdQCaIY//RnhOWrZVoexdqCLH31Ii3Dn:FPYPwbXZq6C7Y/5kWrZVoe/1LH3bDn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144C423D9E1C8622BE67E4B71CC2630EA6011FFF055C26A9BA2EBB11DC0BEC505D57029
sha3_384: 0ccba4c1377ad98ebf8e467e7d739d4932e8adc3d38f25b81e6122b32aa2886f147797021bb86861f0816a216edaccab
ep_bytes: e852fcffffe963fdffff8bff558bec81
timestamp: 2012-11-07 10:37:04

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office 2013 component
FileVersion: 15.0.4454.1000
InternalName: smarttaginstall
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: SmartTagInstall.exe
ProductName: Microsoft Office 2013
ProductVersion: 15.0.4454.1000
Translation: 0x0000 0x04e4

Malware.AI.2488916850 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.H5
ALYacWin32.Expiro.Gen.7
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWVirus ( 0059041f1 )
K7AntiVirusVirus ( 0059041f1 )
CyrenW32/Expiro.AU.gen!Eldorado
ESET-NOD32a variant of Win32/Expiro.CM
APEXMalicious
ClamAVWin.Virus.Expiro-9972211-0
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Vitro [Inf]
TencentVirus.Win32.VirMoiva.a
Ad-AwareWin32.Expiro.Gen.7
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureTrojan.TR/Patched.Gen
VIPREWin32.Expiro.Gen.7
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.14efdc48f7e52697
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.7
GoogleDetected
AviraTR/Patched.Gen
MAXmalware (ai score=81)
Antiy-AVLVirus/Win32.Expiro.x
ArcabitWin32.Expiro.Gen.7
ZoneAlarmVirus.Win32.Moiva.a
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
MalwarebytesMalware.AI.2488916850
RisingTrojan.Generic@AI.77 (RDMK:cmRtazpP1haO7JK1gVXKZrps/FHB)
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.13950c
PandaW32/Moyv.A

How to remove Malware.AI.2488916850?

Malware.AI.2488916850 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment