Malware

What is “Malware.AI.4206191123”?

Malware Removal

The Malware.AI.4206191123 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4206191123 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4206191123?


File Info:

name: 4451FB9441826C313CCE.mlw
path: /opt/CAPEv2/storage/binaries/4e4e13bba272a18cbe1ef181a11b0e11cd5d4dd18bf58ff5e88eb8c954fd6e08
crc32: F8CB69D6
md5: 4451fb9441826c313cce8d4a36f7c8e0
sha1: 799f471a5eb1107dfb47762eebba578067f4f41e
sha256: 4e4e13bba272a18cbe1ef181a11b0e11cd5d4dd18bf58ff5e88eb8c954fd6e08
sha512: 036b46c7f61b6fe18cb043b45adb3e60466b06db3b79e5324202d6633ce5e63483e5a63f93258d79e3f790288368f48feda6bbe9d306cbea8c4876dde9cb4852
ssdeep: 24576:+Ni8cfLyqVfPweH2k5DVWpLGyrU3ODEg6fi9kdQXVM:gc+qVfPweHr6n9eUM
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1074516B09E9FD9CAC12F623FB7450942A4AFE6021313C2C747554A742BDE6E7CD36292
sha3_384: 9119409f9c74d8efca90fe1c0b765f7e7b392fcbd282509188587940093d5f37f970c4aa6eba4d6e9b8b2d0986df7899
ep_bytes: 455357455541bb60000000654b8b3b52
timestamp: 2021-09-13 06:20:49

Version Info:

CompanyName: NVIDIA Corporation
FileDescription: NVIDIA ShadowPlay Helper
FileVersion: 3.24.0.123
InternalName: nvsphelper.exe
LegalCopyright: (C) 2020 NVIDIA Corporation. All rights reserved.
OriginalFilename: nvsphelper.exe
ProductName: NVIDIA GeForce Experience
ProductVersion: 3.24.0.123
Translation: 0x0009 0x04b0

Malware.AI.4206191123 also known as:

LionicVirus.Win32.Expiro.n!c
Elasticmalicious (high confidence)
DrWebWin64.Expiro.133
MicroWorld-eScanWin64.Expiro.Gen.6
FireEyeGeneric.mg.4451fb9441826c31
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/Raccoon.3aab33c6
CyrenW64/Expiro.AO.gen!Eldorado
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win64/Expiro.CO
TrendMicro-HouseCallVirus.Win64.EXPIRO.MR
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderWin64.Expiro.Gen.6
AvastWin64:Xpirat [Inf]
TencentWin64.Virus.Expiro.Pbfd
Ad-AwareWin64.Expiro.Gen.6
EmsisoftWin64.Expiro.Gen.6 (B)
TrendMicroVirus.Win64.EXPIRO.MR
McAfee-GW-EditionBehavesLike.Win64.CoinMiner.th
SophosMal/Generic-S
IkarusVirus.Win64.Expiro
GDataWin64.Expiro.Gen.6
JiangminTrojan.Scar.tsz
AviraW64/Infector.Gen
MicrosoftTrojan:Win32/Raccoon.EC!MTB
CynetMalicious (score: 100)
Acronissuspicious
ALYacWin64.Expiro.Gen.6
MAXmalware (ai score=89)
MalwarebytesMalware.AI.4206191123
APEXMalicious
FortinetW64/Expiro.CE
AVGWin64:Xpirat [Inf]
Cybereasonmalicious.441826

How to remove Malware.AI.4206191123?

Malware.AI.4206191123 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment