Malware

Malware.AI.4073967562 (file analysis)

Malware Removal

The Malware.AI.4073967562 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4073967562 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4073967562?


File Info:

name: 04F9C5A5F41DDCCA08D0.mlw
path: /opt/CAPEv2/storage/binaries/45ee253c25181a325f4faa08d2b62eed1c8641625f8cff2f09ff14da83bdd25c
crc32: C602B4FF
md5: 04f9c5a5f41ddcca08d0c9a38c5a647b
sha1: 68b8dd51c795aa1b45d95f35c81a47f44349c582
sha256: 45ee253c25181a325f4faa08d2b62eed1c8641625f8cff2f09ff14da83bdd25c
sha512: 3f7fccf9a943ed0a252ee007ce3b6ad9ea8ab424c58b46586946cf9c63de52fbd340ae525806c2a424ca9adcb7410906d5b3c735ac9455c19f88251c486526b9
ssdeep: 12288:B9HkdEi3G8KNJNlTonx/RhBPhol4DYmmBmvOLyC:B9HkeiW8mlTcx/pJSqXTmLy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198A47D74E25030DCD52BAF38F5E9B990895C77612306A4A39CEB584A02BCFDB43F4997
sha3_384: 3ffa98844fbc367bfa11ea327ce3ace5e90af7d5b539bc734913501f4eec3d5db3b722c586137189c1c1aec76bd6e3f8
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2014-01-04 21:33:53

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Acrobat Update Service
FileVersion: 1.701.3.3014
InternalName: armsvc.exe
LegalCopyright: Copyright © 2013 Adobe Systems Incorporated. All rights reserved.
OriginalFilename: armsvc.exe
ProductName: Adobe Acrobat Update Service
ProductVersion: 1.701.3.3014
Translation: 0x0409 0x04b0

Malware.AI.4073967562 also known as:

LionicVirus.Win32.Expiro.lVNv
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
ALYacWin32.Expiro.Gen.6
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00561cbf1 )
AlibabaTrojan:Win32/Expiro.be4e94c1
K7GWTrojan ( 00561cbf1 )
Cybereasonmalicious.5f41dd
CyrenW32/Expiro.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDG
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Scar.tizd
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
TencentVirus.Win32.Expiro.ns
Ad-AwareWin32.Expiro.Gen.6
SophosML/PE-A + Mal/EncPk-MK
VIPREVirus.Win32.Expiro.dp (v)
TrendMicroVirus.Win32.EXPIRO.AD
McAfee-GW-EditionBehavesLike.Win32.Virus.gc
FireEyeGeneric.mg.04f9c5a5f41ddcca
EmsisoftWin32.Expiro.Gen.6 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.6
AviraW32/Infector.Gen8
MAXmalware (ai score=82)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4073967562
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.4073967562?

Malware.AI.4073967562 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment