Malware

Malware.AI.4266746482 removal guide

Malware Removal

The Malware.AI.4266746482 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4266746482 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4266746482?


File Info:

name: 2E8C7060AF9B9FB6684E.mlw
path: /opt/CAPEv2/storage/binaries/f5f27c3807417873b4d122bd504dde6b1d2ef934a3ad746d1442c60496fcab76
crc32: 2B72D1CE
md5: 2e8c7060af9b9fb6684ea79e2a39d5ed
sha1: 0a66e36517237bc7815df6b8c987c5a9364e146f
sha256: f5f27c3807417873b4d122bd504dde6b1d2ef934a3ad746d1442c60496fcab76
sha512: 512776c39795368e6c74d56b6d0a6c566f3ffd839d2b7af8f756f4912233c8a14aaa8a48a6bf5d9d0681886b03b29a0fa56c05cfa769048216c15cbb4ab93620
ssdeep: 6144:NZ9EOK99kXYS1ZtSbUVbwaoQtN2BWRSFGmOGQFMNqnmZ9O3r8uptHUt:NvYZNcc4sGEQFMNqnmZ43rRptHU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8A49DC3A24D05C4DF6831F29BEABB08E17982D5DF94B9085FD9BC3A08B9AC154487DD
sha3_384: cb64c0ab178d7d476f530debb4b057630a7d67893482b22586604f8e07847a9f8f1ec8b0673e5a8aed3cb7f278661fcc
ep_bytes: 535751bb18000000648b3b03db01fb8b
timestamp: 2009-07-18 22:00:54

Version Info:

CompanyName: Microsoft Corporation
FileDescription: .NET Runtime Optimization Service
FileVersion: 2.0.50727.4927 (NetFXspW7.050727-4900)
InternalName: mscorsvw.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: mscorsvw.exe
ProductName: Microsoft® .NET Framework
ProductVersion: 2.0.50727.4927
Comments: Flavor=Retail
Translation: 0x0409 0x04b0

Malware.AI.4266746482 also known as:

BkavW32.Expiro2NHc.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.2e8c7060af9b9fb6
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.0af9b9
VirITWin32.Expiro.CW
CyrenW32/Expiro.AX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.CP
APEXMalicious
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
TencentVirus.Win32.Expiro.ns
Ad-AwareWin32.Expiro.Gen.6
EmsisoftWin32.Expiro.Gen.6 (B)
VIPREWin32.Expiro.Gen.6
TrendMicroVirus.Win32.EXPIRO.AD
McAfee-GW-EditionBehavesLike.Win32.Expiro.gc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-MK
SentinelOneStatic AI – Malicious PE
GDataWin32.Expiro.Gen.6
JiangminTrojan.Bingoml.esh
GoogleDetected
AviraTR/Patched.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASVirus.332
ArcabitWin32.Expiro.Gen.6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32BScope.Trojan.Wacatac
ALYacWin32.Expiro.Gen.6
MalwarebytesMalware.AI.4266746482
TrendMicro-HouseCallVirus.Win32.EXPIRO.AD
IkarusVirus.Win32.Expiro
AVGWin32:Xpirat-C [Inf]
PandaW32/Expiro.AK
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.4266746482?

Malware.AI.4266746482 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment