Malware

Malware.AI.4250545379 removal

Malware Removal

The Malware.AI.4250545379 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4250545379 virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Likely virus infection of existing system binary
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to create or modify system certificates
  • Creates a slightly modified copy of itself

How to determine Malware.AI.4250545379?


File Info:

crc32: C9651FB1
md5: 5a2ea9d219715981d82d3a85f4264dda
name: 5A2EA9D219715981D82D3A85F4264DDA.mlw
sha1: b380f8a26143af0eaa0fb6266d9f7411dbc0c1ff
sha256: 33d14936281f984613be68485e0e54591aafdb2d47caf4e9377a42f1103d4857
sha512: dd0bea738fa5c5c626820ce3f337dc252d8a2e0967bb0c0a56bd3873318c95986096a2b8c6dba60b48b4406d537c6f8a060fb4e1213e3a824df72ea1f4e0f59a
ssdeep: 12288:0C6SX/CfmsviGOyKLIuxTIvlJ8lBd2jqpcmJH2Jf/Uc:0C6SXsfiGNSITQlzO8cmM
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: cmd
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Windows Command Processor
OriginalFilename: Cmd.Exe
Translation: 0x0409 0x04b0

Malware.AI.4250545379 also known as:

K7AntiVirusVirus ( 00580a951 )
Elasticmalicious (high confidence)
DrWebWin32.Expiro.153
ALYacWin32.Expiro.Gen.6
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderWin32.Expiro.Gen.6
K7GWVirus ( 00580a951 )
Cybereasonmalicious.219715
CyrenW32/Expiro.AH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Expiro.NDJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Virus.Win32.Expiro.gen
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanWin32.Expiro.Gen.6
Ad-AwareWin32.Expiro.Gen.6
SophosML/PE-A + Mal/EncPk-MK
VIPREVirus.Win32.Expiro.dp (v)
TrendMicroVirus.Win32.EXPIRO.AD
FireEyeGeneric.mg.5a2ea9d219715981
EmsisoftWin32.Expiro.Gen.6 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Gen
Antiy-AVLVirus/Win32.Expiro.ndg
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitWin32.Expiro.Gen.6
ZoneAlarmHEUR:Virus.Win32.Expiro.gen
GDataWin32.Expiro.Gen.6
Acronissuspicious
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4250545379
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.NDG!tr

How to remove Malware.AI.4250545379?

Malware.AI.4250545379 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment