Malware

Malware.AI.3924961466 removal instruction

Malware Removal

The Malware.AI.3924961466 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3924961466 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a hidden or system file

How to determine Malware.AI.3924961466?


File Info:

name: 042F4C2F54659CFA1899.mlw
path: /opt/CAPEv2/storage/binaries/1d44abd2914c5427cc5a598ad6e7d6344507f568fb6594f54eb35bc53f108bf5
crc32: 79629F1F
md5: 042f4c2f54659cfa1899ff5130394d47
sha1: 5919031274052e945c09aa10a3e7bb05be9acf87
sha256: 1d44abd2914c5427cc5a598ad6e7d6344507f568fb6594f54eb35bc53f108bf5
sha512: 018f82840caea57b31bca3077ef3b02f952bed99a25cb9cd8ab5999bc73efc3f5b49de7981dac8ec01d3eef7b5054fd2b59fa1b88c3b4b7232a662ce0cb4d13a
ssdeep: 12288:Dts5J+4/ovSLFcS+snWkBnMD9Z8UO76g95TEPQuPn4OzCrXHiiVNzHTkr2P:Dm3/oqCRJT1Qon4yWXHiizrIE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16215CF78D6147CCFC47BBF38F5D9B994C9E42390221A5462ACEF19C90EAC72A8364D47
sha3_384: 088843ea8bc4773f8c814c35ebb1a989f798d9b34eab784204afe8964102f5c4ed733015e6454626fe6b6665b5c33577
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2005-05-21 11:59:13

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Self-Extracting Cabinet
FileVersion: 6.1.0022.4 (SRV03_QFE.031113-0918)
InternalName: SFXCAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SFXCAB.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.0022.4
Translation: 0x0409 0x04b0

Malware.AI.3924961466 also known as:

MicroWorld-eScanGen:Variant.Babar.51969
FireEyeGeneric.mg.042f4c2f54659cfa
McAfeeTrojan-FUNU!042F4C2F5465
MalwarebytesMalware.AI.3924961466
K7AntiVirusVirus ( 0058dc741 )
BitDefenderGen:Variant.Babar.51969
K7GWVirus ( 0058dc741 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITWin32.Expiro.CV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.CP
ClamAVWin.Virus.Expiro-9916822-0
KasperskyVirus.Win32.Expiro.ns
NANO-AntivirusVirus.Win32.Gen.ccmw
Ad-AwareGen:Variant.Babar.51969
SophosMal/Generic-S
DrWebWin32.Expiro.150
VIPREGen:Variant.Babar.51969
McAfee-GW-EditionTrojan-FUNU!042F4C2F5465
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Babar.51969 (B)
APEXMalicious
JiangminTrojan.PSW.Stealer.abj
AviraW32/Infector.Gen8
Antiy-AVLTrojan/Generic.ASVirus.315
MicrosoftTrojan:Win32/Raccoon.EC!MTB
ZoneAlarmHEUR:Trojan.Win32.Expiro.gen
GDataGen:Variant.Babar.51969
CynetMalicious (score: 99)
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Babar.51969
MAXmalware (ai score=84)
CylanceUnsafe
PandaGeneric Suspicious
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.274052
AvastWin32:Xpirat-C [Inf]

How to remove Malware.AI.3924961466?

Malware.AI.3924961466 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment