Malware

Should I remove “Malware.AI.4149527745”?

Malware Removal

The Malware.AI.4149527745 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4149527745 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.4149527745?


File Info:

name: 977B5BDFD9468D2E414D.mlw
path: /opt/CAPEv2/storage/binaries/699b724afd8aa7ec1a3c85e076ffd46f993c7c583f80407591acfb039657b619
crc32: BB720502
md5: 977b5bdfd9468d2e414dbe78ac5285f6
sha1: fa55234a90c763b52ab7e857c35917b2cb2417c0
sha256: 699b724afd8aa7ec1a3c85e076ffd46f993c7c583f80407591acfb039657b619
sha512: 286feae6c632e501469a9fcde1c3f3c55b06b7e3bcade877bbc9983f13a1357789089b68180183f65dba97e7e7098c94fbef7f489ee02cbbcbeb8179b23ec41a
ssdeep: 98304:Q3HRyq2mAiJ7qY93Dw/9tkkeCcmZllfu:dmAiJ7R98ckeWZll
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4F5AF22B7858077E0B3017057B8A365A6B8F7312B3144CB63C17B5E6B74AC17E36A5B
sha3_384: 0870957b21fdc90b06982afc71ef1e2aa928d79fdfae4b76f0aa085abb0a8be0f5536be67a91884d136036537cb4ce13
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2051-04-18 06:53:29

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Standalone Updater
InternalName: OneDriveStandaloneUpdater.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: OneDriveStandaloneUpdater.exe
ProductName: Microsoft OneDrive
FileVersion: 21.220.1024.0005
ProductVersion: 21.220.1024.0005
SpecialBuild: b/build/2c205c5c-e050-0ffd-f7d0-63786687edbc
Translation: 0x0409 0x04b0

Malware.AI.4149527745 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.977b5bdfd9468d2e
ALYacWin32.Expiro.Gen.6
VIPREVirus.Win32.Expiro.dp (v)
K7AntiVirusVirus ( 0058dc741 )
BitDefenderWin32.Expiro.Gen.6
K7GWVirus ( 0058dc741 )
CrowdStrikewin/malicious_confidence_60% (D)
VirITWin32.Expiro.CV
CyrenW32/Expiro.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.CP
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
ClamAVWin.Trojan.Expiro-9918973-0
KasperskyVirus.Win32.Expiro.ns
NANO-AntivirusVirus.Win32.Gen.ccmw
SophosMal/EncPk-MK
DrWebWin32.Expiro.150
TrendMicroVirus.Win32.EXPIRO.AD
SentinelOneStatic AI – Suspicious PE
EmsisoftWin32.Expiro.Gen.6 (B)
APEXMalicious
JiangminTrojan.PSW.Stealer.abj
AviraW32/Infector.Gen8
Antiy-AVLTrojan/Generic.ASVirus.315
MicrosoftTrojan:Win32/Raccoon.EC!MTB
ZoneAlarmVirus.Win32.Expiro.ns
GDataWin32.Expiro.Gen.6
CynetMalicious (score: 100)
MAXmalware (ai score=81)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4149527745
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG
AVGWin32:Xpirat-C [Inf]
Cybereasonmalicious.fd9468
AvastWin32:Xpirat-C [Inf]

How to remove Malware.AI.4149527745?

Malware.AI.4149527745 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment