Malware

Malware.AI.4065917391 removal

Malware Removal

The Malware.AI.4065917391 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4065917391 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4065917391?


File Info:

name: C73236A30D3FA508606D.mlw
path: /opt/CAPEv2/storage/binaries/2973c6a58962b0b3b7187122aa684221210189a1117f706e37cdfc664521ae46
crc32: 3F6B3227
md5: c73236a30d3fa508606d424f8394d2f6
sha1: 85463e1556ce4429f6a393f67585fad3b9f00e85
sha256: 2973c6a58962b0b3b7187122aa684221210189a1117f706e37cdfc664521ae46
sha512: a7cd2546a192b65740440ed62f8e4b15846436be7e425e60c33da7f7c54639826c2999e4944738a1481e88174b7193909073ae00ffb3d4ed2fe7cf6c517d5a8e
ssdeep: 12288:6AVQjJOMAJy8VR9sR2s8J2uBzhRcJ7CyY:5zMhaB74UgJ73Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173947B77A62024FCFFEA5F3834C9B88C984C265C62165113ACEF9959C2F87A643F4947
sha3_384: 0e54f56d643bbef29d590cc61900ec640501f4207f0dcf9517d4643a12cfc18d2166a62029913bb7f4e44405affa7be1
ep_bytes: 535751bb18000000648b3b03db01fb8b
timestamp: 2009-11-10 20:12:01

Version Info:

CompanyName: Microsoft Corporation
FileDescription: COM Surrogate
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: dllhost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dllhost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Malware.AI.4065917391 also known as:

BkavW32.Expiro2NHc.PE
MicroWorld-eScanWin32.Expiro.Gen.6
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.30d3fa
VirITWin32.Expiro.CW
CyrenW32/Expiro.AX.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Expiro.CP
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
CynetMalicious (score: 100)
APEXMalicious
TencentVirus.Win32.Expiro.ns
Ad-AwareWin32.Expiro.Gen.6
EmsisoftWin32.Expiro.Gen.6 (B)
VIPREWin32.Expiro.Gen.6
McAfee-GW-EditionBehavesLike.Win32.Virut.gc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c73236a30d3fa508
SophosML/PE-A + Mal/EncPk-MK
IkarusVirus.Win32.Expiro
GDataWin32.Expiro.Gen.6
JiangminTrojan.Bingoml.esh
AviraW32/Infector.Gen8
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASVirus.332
ArcabitWin32.Expiro.Gen.6
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GoogleDetected
AhnLab-V3Malware/Win.Generic.R426283
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacWin32.Expiro.Gen.6
MalwarebytesMalware.AI.4065917391
AvastWin32:Xpirat-C [Inf]
SentinelOneStatic AI – Malicious PE
FortinetW32/Expiro.CP
AVGWin32:Xpirat-C [Inf]
PandaW32/Expiro.AK
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.4065917391?

Malware.AI.4065917391 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment