Malware

How to remove “Malware.AI.3707746630”?

Malware Removal

The Malware.AI.3707746630 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3707746630 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.3707746630?


File Info:

name: 52FC264D4F275ADA6D5C.mlw
path: /opt/CAPEv2/storage/binaries/4a30c10f17cb19156752ece721ee20c5d7f7509238dd1511d94972b72bbc1a82
crc32: 88873B85
md5: 52fc264d4f275ada6d5c7bf17b69ed62
sha1: 57086da391e80b1adc71ffde03784d79ac4a460b
sha256: 4a30c10f17cb19156752ece721ee20c5d7f7509238dd1511d94972b72bbc1a82
sha512: 43b86ebc6409d7678099529b5143402bd4069f9948868c5b0dc640d9a8ff3db427e8cb67e257455a1b20b7c53ad604dc8f55e869f65d44cb8720f61a3b1a91e8
ssdeep: 12288:+nLW1U4hv4qt6/bsZxnFxdgbE06KG4SG:+nSU4hvPjnF/H06KI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4A47C7CA77435CCD53F6E7839D9F7808A5437A02F16945E5CEB184A01A8BBA8374B83
sha3_384: 39f9c7f2c1440388e1a0820da0160150b01d17224d8ed992ad50f7e21d9572a20fd0657a9a9f582d60d94268ddd70577
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2009-06-30 08:10:46

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Certificate Enrollment Control
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: EnrollComServer.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: EnrollComServer.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Malware.AI.3707746630 also known as:

BkavW32.Expiro2NHc.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.52fc264d4f275ada
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 0058dc741 )
K7GWVirus ( 0058dc741 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITWin32.Expiro.CV
CyrenW32/S-4367e7a0!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.CP
APEXMalicious
ClamAVWin.Virus.Expiro-9937158-0
KasperskyVirus.Win32.Expiro.ns
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
TencentVirus.Win32.Expiro.ns
EmsisoftWin32.Expiro.Gen.6 (B)
DrWebWin32.Expiro.150
VIPREVirus.Win32.Expiro.dp (v)
SophosML/PE-A + Mal/EncPk-MK
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Stealer.abj
AviraTR/Patched.Gen
Antiy-AVLTrojan/Generic.ASVirus.315
MicrosoftTrojan:Win32/Raccoon.EC!MTB
ZoneAlarmVirus.Win32.Expiro.ns
GDataWin32.Expiro.Gen.6
CynetMalicious (score: 100)
ALYacWin32.Expiro.Gen.6
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.3707746630
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.d4f275

How to remove Malware.AI.3707746630?

Malware.AI.3707746630 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment