Malware

Should I remove “Malware.AI.4232471372”?

Malware Removal

The Malware.AI.4232471372 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4232471372 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.4232471372?


File Info:

name: DB3B89025454BF798380.mlw
path: /opt/CAPEv2/storage/binaries/835b657ffb49a7e90fda87c30969ee6fdc05e8a4e01ac83d7017719eb77126a3
crc32: D248201F
md5: db3b89025454bf7983808f26b58dc004
sha1: 430cc87f97d7afa77697524ed249639ecb3d525f
sha256: 835b657ffb49a7e90fda87c30969ee6fdc05e8a4e01ac83d7017719eb77126a3
sha512: 402b9f8bb4661531cbabd4107064423637add6aeaa185552bf16748f8e4f9e2f85d8dcaa63871c5c69e1418f30d5bdd1178cb8e2dd713d268c98bb80065ef357
ssdeep: 24576:RbmxtSP+sJ+O5FWPPw4Rl9Z06eLSOZ/X:Rb3MTI4Rl9Z09jX
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1E515AD817714F289D9298C3159D2E6B5C6F16DB2DE2B09C73BB57F2E2CB3013211726A
sha3_384: f93bb9bd9d1b5c620a665b56b9a80a75ac93073259e77420323d0ef2e2451387364e5f577df9c6ec23b5d6ad2eafbbcb
ep_bytes: 475150455243b96000000065498b0145
timestamp: 2012-04-11 15:27:24

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Contacts
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
InternalName: WAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WAB.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.17134.1
Translation: 0x0409 0x04b0

Malware.AI.4232471372 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin64.Expiro.Gen.6
FireEyeGeneric.mg.db3b89025454bf79
CylanceUnsafe
K7AntiVirusVirus ( 00535e4a1 )
K7GWVirus ( 00535e4a1 )
Cybereasonmalicious.f97d7a
CyrenW64/Expiro.AH.gen!Eldorado
ESET-NOD32a variant of Win64/Expiro.CO
TrendMicro-HouseCallVirus.Win64.EXPIRO.MR
ClamAVWin.Virus.Expiro-9896262-0
KasperskyHEUR:Virus.Win64.Expiro.gen
BitDefenderWin64.Expiro.Gen.6
NANO-AntivirusVirus.Win64.Expiro.clnvwd
AvastWin64:Xpirat [Inf]
Ad-AwareWin64.Expiro.Gen.6
EmsisoftWin64.Expiro.Gen.6 (B)
DrWebWin64.Expiro.132
TrendMicroVirus.Win64.EXPIRO.MR
SophosML/PE-A + W64/Expiro-AX
SentinelOneStatic AI – Malicious PE
GDataWin64.Expiro.Gen.6
JiangminTrojan.Bingoml.akq
MAXmalware (ai score=88)
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
ALYacWin64.Expiro.Gen.6
MalwarebytesMalware.AI.4232471372
IkarusVirus.Win64.Expiro
MaxSecurevirus.win64.expiro.gen
FortinetW64/Expiro.BS
AVGWin64:Xpirat [Inf]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Malware.AI.4232471372?

Malware.AI.4232471372 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment