Malware

Should I remove “Malware.AI.4186429863”?

Malware Removal

The Malware.AI.4186429863 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4186429863 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.4186429863?


File Info:

name: B87559580E39318CEF0E.mlw
path: /opt/CAPEv2/storage/binaries/821375dbfef720fdb3a5e754919f8a314abc5a627128f7ea0aacd4e2be13b40d
crc32: 6DA98078
md5: b87559580e39318cef0e0864262d6b0f
sha1: 68be397dffd1db5bfb8e152e4b423aa9438e74a3
sha256: 821375dbfef720fdb3a5e754919f8a314abc5a627128f7ea0aacd4e2be13b40d
sha512: 4180ef4ece99f82f82543e48853471a3cefa6e0532b9a1c607b0ea0220ebd30ef8022c996a17d5de904eda4c8f62f4d1721f00ba691259efc658d99857799e65
ssdeep: 49152:XjFX33t4INnfTqkUMLu/52bulcI1wXZTBz5BkG/7A:XJfTqmeX1TGjA
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T16CA59E13E58411D9D0A9D4389B41BD33DA76BC2A1B20B6CF1341A3492A76AF49B3DF1F
sha3_384: 41412f7ad7864a11e92980829c51c9386ca626d7a192e773391f7721f71f759288a79860dc05122be46ef02c36bcc099
ep_bytes: 90554889e55648ffce57415441554156
timestamp: 2021-08-11 22:26:40

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge
FileVersion: 92.0.902.73
InternalName: elevation_service_exe
LegalCopyright: Copyright Microsoft Corporation. All rights reserved.
OriginalFilename: elevation_service.exe
ProductName: Microsoft Edge
ProductVersion: 92.0.902.73
CompanyShortName: Microsoft
ProductShortName: Microsoft Edge
LastChange: cad199e39220991414cd71868a619fff614880c7
Official Build: 1
Translation: 0x0409 0x04b0

Malware.AI.4186429863 also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.b87559580e39318c
McAfeeW64/Expiro.a
CylanceUnsafe
ZillyaVirus.Expiro.Win64.34
K7AntiVirusVirus ( 0040f8071 )
K7GWVirus ( 0040f8071 )
CrowdStrikewin/malicious_confidence_90% (D)
BaiduWin64.Virus.Expiro.r
CyrenW64/Expiro.D!gen
SymantecW64.Xpiro.F
ESET-NOD32Win64/Expiro.AG
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win64.Expiro.g
BitDefenderWin64.Expiro.Gen.3
NANO-AntivirusVirus.Win64.Expiro.dtfhve
MicroWorld-eScanWin64.Expiro.Gen.3
AvastWin32:Expiro-DD
TencentVirus.Win64.Expiro.ad
Ad-AwareWin64.Expiro.Gen.3
DrWebWin64.Expiro.108
VIPREVirus.Win64.Expiro.gen.a (v)
TrendMicroPE64_EXPIRO.AR
McAfee-GW-EditionBehavesLike.Win64.Dropper.vh
EmsisoftWin64.Expiro.Gen.3 (B)
SentinelOneStatic AI – Suspicious PE
AviraW64/Expiro.AF
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASVirus.311
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin64.Expiro.Gen.3
AhnLab-V3Win64/Expiro2.Gen
Acronissuspicious
ALYacWin64.Expiro.Gen.3
TACHYONVirus/W64.Expiro.C
MalwarebytesMalware.AI.4186429863
TrendMicro-HouseCallPE64_EXPIRO.AR
RisingVirus.Expiro!1.A140 (CLASSIC)
IkarusVirus.Win64.Expiro
MaxSecurevirus.win64.expiro.gen
FortinetW64/Expiro.Q
AVGWin32:Expiro-DD
PandaW32/Expiro.gen

How to remove Malware.AI.4186429863?

Malware.AI.4186429863 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment