Malware

Malware.AI.4190113505 (file analysis)

Malware Removal

The Malware.AI.4190113505 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4190113505 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4190113505?


File Info:

name: 6F1A06D9A84F5DE9A6B2.mlw
path: /opt/CAPEv2/storage/binaries/2461aa19788ae2662d2fb3b05647889d601b032233f88c45f0e2e08cb061cd5e
crc32: AFEB1A08
md5: 6f1a06d9a84f5de9a6b2b7dc58e01982
sha1: 2005d2644449c5e21d93305fd6dd27ededddef6c
sha256: 2461aa19788ae2662d2fb3b05647889d601b032233f88c45f0e2e08cb061cd5e
sha512: 3b423c53cc558eb1250db8e274926cfeefd22358ca5c15e0c307f2b8a4c6698852007475f8a1f005188948e5dd25d350f0c6f1b290b74efcf583d02fd899c5a1
ssdeep: 12288:np6SX/CfmXzVjjSvi3XRf5XSkSEbF2Pg+kVtk:np6SXsAzVjjSvi35FvQMVt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B7E48C836234D5E3CB6921315EAAFBF4E57A0E71DE18D940B9C1BF3B287DA8074184D9
sha3_384: 17f5c30c2f8fa58795588dc691fee926fb252be77ce8429e218b6dc800f983d7447ab064bf7c5261db69a0f8e5447b5d
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2010-08-04 01:14:54

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Command Processor
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
InternalName: cmd
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Cmd.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Malware.AI.4190113505 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
ClamAVWin.Virus.Expiro-9923974-0
FireEyeGeneric.mg.6f1a06d9a84f5de9
McAfeeTrojan-FUNU!6F1A06D9A84F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 0058dc741 )
K7GWTrojan ( 0058bbae1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWin32.Expiro.CV
CyrenW32/Expiro.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.CP
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Expiro.ns
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
Ad-AwareWin32.Expiro.Gen.6
EmsisoftWin32.Expiro.Gen.6 (B)
DrWebWin32.Expiro.150
VIPREWin32.Expiro.Gen.6
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-MK
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.P6P8TP
JiangminTrojan.PSW.Stealer.abj
AviraTR/Patched.Gen
Antiy-AVLTrojan/Generic.ASVirus.315
ArcabitWin32.Expiro.Gen.6
ZoneAlarmHEUR:Trojan.Win32.Expiro.gen
MicrosoftTrojan:Win32/Raccoon.EC!MTB
GoogleDetected
AhnLab-V3Virus/Win.Expiro.X2160
ALYacWin32.Expiro.Gen.6
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4190113505
IkarusVirus.Win32.Expiro
AVGWin32:Xpirat-C [Inf]

How to remove Malware.AI.4190113505?

Malware.AI.4190113505 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment