Malware

Malware.AI.977478583 (file analysis)

Malware Removal

The Malware.AI.977478583 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.977478583 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.977478583?


File Info:

name: 73379ADE12FCD65AB4A2.mlw
path: /opt/CAPEv2/storage/binaries/f19abfac8689696b292c732b1b7bad2f1b2fb640424cc64e5a2b0c3304561f9b
crc32: 4967C550
md5: 73379ade12fcd65ab4a2075677562cd8
sha1: 75f47c4210a76beaa51644d321ea89f9363e4018
sha256: f19abfac8689696b292c732b1b7bad2f1b2fb640424cc64e5a2b0c3304561f9b
sha512: c7a047281ec8e59b277db3950f6a4a4745f4453ecf59f65e0d9ea5b07eae38c178fdee60eceb8d7d802f1be430076164dee5a8f73ff7ab35df6ed49097a2c931
ssdeep: 24576:MNQ+9+MzVdi/DZgQzYM65mpXNgbUDGTgl1Y9IrQCYlWn2jxRN9xwnrXiVk:49HhQruM65mp9DG0l1Y9IrQ5IExmW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1459E2676C8C520E1734131EAACA228716AF439AB79B19FF398535D2C74DC31E34B5B
sha3_384: 38e1815a53a58ffbd7eb8fd1d97e52961baf1249102d24a9ddd08b6d8a1e4b6a77a76987a12ed17c4f30842c1406dc54
ep_bytes: 505753b830000000648b38518bc783c0
timestamp: 2000-07-07 17:04:13

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Search Indexer
FileVersion: 7.0.17134.1304 (WinBuild.160101.0800)
InternalName: SearchIndexer.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SearchIndexer.exe
ProductName: Windows® Search
ProductVersion: 7.0.17134.1304
Translation: 0x0409 0x04b0

Malware.AI.977478583 also known as:

Elasticmalicious (high confidence)
DrWebWin32.Expiro.150
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.73379ade12fcd65a
ALYacWin32.Expiro.Gen.6
MalwarebytesMalware.AI.977478583
K7AntiVirusVirus ( 00580a951 )
K7GWVirus ( 00580a951 )
Cybereasonmalicious.e12fcd
CyrenW32/Expiro.W.gen!Eldorado
ESET-NOD32Win32/Expiro.CL
TrendMicro-HouseCallVirus.Win32.EXPIRO.AF
ClamAVWin.Virus.Expiro-9879690-0
KasperskyVirus.Win32.Expiro.ns
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
TencentVirus.Win32.Expiro.ns
Ad-AwareWin32.Expiro.Gen.6
EmsisoftWin32.Expiro.Gen.6 (B)
F-SecureTrojan.TR/Patched.Gen
VIPREVirus.Win32.Expiro.dp (v)
TrendMicroVirus.Win32.EXPIRO.AF
SophosML/PE-A + W32/Expiro-AU
SentinelOneStatic AI – Suspicious PE
GDataWin32.Expiro.Gen.6
JiangminTrojan.Generic.gcshv
AviraTR/Patched.Gen
MAXmalware (ai score=80)
Antiy-AVLVirus/Win64.Expiro.rc
ArcabitWin32.Expiro.Gen.6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Virus/Win.Expiro.X2115
Acronissuspicious
VBA32BScope.Trojan.Wacatac
APEXMalicious
IkarusVirus.Win32.Expiro
FortinetW32/Expiro.RC!tr
AVGWin32:Xpirat-C [Inf]

How to remove Malware.AI.977478583?

Malware.AI.977478583 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment