Malware

Malware.AI.736881757 information

Malware Removal

The Malware.AI.736881757 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.736881757 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.736881757?


File Info:

name: 14E9CAB2FC0545BAFDC8.mlw
path: /opt/CAPEv2/storage/binaries/642687ce8d398498df82e8376db094e8b8f1524ac637149e262bab4cddb98743
crc32: 378508DF
md5: 14e9cab2fc0545bafdc87edcd5d1f285
sha1: fed418ef13a139583d437ad9e1d804503315e8ec
sha256: 642687ce8d398498df82e8376db094e8b8f1524ac637149e262bab4cddb98743
sha512: 9c75051fb9c28093caf29e571c3a25e3ca9dc9ef33ad0e5d43429b3b6041a911477c1ad4f14eb803498c95271580ebee36b3940f0943408566e0f1694fd98b5e
ssdeep: 24576:S6nUM4X0AbEdeJgCpf0JNflyOg5eW6OH2kxJv+LvG5hq8LgB:bnV4X0AbEdeJgCpf0/tyOM6szm+o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E255A01EEABC8DEC52B223F791BBB4250AED3304B1395C65F841C3976A45DB5C274EA
sha3_384: 7a76428256302e1f749aa5f169a922bb8d475f88b3a0216114ddcc61d7aa207c2d77452355a9c8a65f3f1a56f21c3c91
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2021-12-18 23:56:17

Version Info:

CompanyName: NVIDIA Corporation
FileDescription: NVIDIA nodejs launcher
FileVersion: 3.24.0.123
InternalName: NVIDIA nodejs launcher
LegalCopyright: (C) 2020 NVIDIA Corporation. All rights reserved.
OriginalFilename: nvnodejslauncher.exe
ProductName: NVIDIA GeForce Experience
ProductVersion: 3.24.0.123
Translation: 0x0409 0x04b0

Malware.AI.736881757 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.14e9cab2fc0545ba
ALYacWin32.Expiro.Gen.6
Cybereasonmalicious.2fc054
CyrenW32/Expiro.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDG
APEXMalicious
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
Ad-AwareWin32.Expiro.Gen.6
SophosML/PE-A + Mal/EncPk-MK
VIPREVirus.Win32.Expiro.dp (v)
McAfee-GW-EditionBehavesLike.Win32.BadFile.fc
EmsisoftWin32.Expiro.Gen.6 (B)
SentinelOneStatic AI – Suspicious PE
AviraW32/Infector.Gen8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Expiro.Gen.6
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4830292
Acronissuspicious
McAfeeArtemis!14E9CAB2FC05
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.736881757
RisingMalware.Heuristic!ET#90% (RDMK:cmRtazrgl80RfLhhH7/q/RPvOvdo)
FortinetW32/Expiro.NDG
BitDefenderThetaGen:NN.ZexaF.34084.@u0@aC8A2cli
AVGWin32:Xpirat-C [Inf]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.736881757?

Malware.AI.736881757 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment