Malware

Malware.AI.507195241 removal guide

Malware Removal

The Malware.AI.507195241 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.507195241 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.507195241?


File Info:

name: AF593451721014F27746.mlw
path: /opt/CAPEv2/storage/binaries/d2ee36630345199b4324595d2b5590013d63d2ab0d3658499090c7d46cf3554e
crc32: FBE2DF21
md5: af593451721014f277464c2c53447102
sha1: 79212ab5ad9176ed2e8d25ac86ddc55b7341f485
sha256: d2ee36630345199b4324595d2b5590013d63d2ab0d3658499090c7d46cf3554e
sha512: 2f48c52bcea14cd5a334a0ac9b92b9c944e73726ee7b9727ea333388a4529c2e0fdbf24ac02299057f3f549a6d312a4c170e7a45ba625c84c4a8f550f8b17c49
ssdeep: 49152:ku5HOTnC551DtoZAMD0vXDljYIgekrhbuRKwpB:3HZiOOOiekrH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F7E57D2277F49021E1BB0A7159B1E73296317D111F368ACFE258B65E1E337C1AA39723
sha3_384: 598911d4d1a923f78b177c4d093be038b0d93ad4e78283c45d38059366e4042941f757a592efd934661cf636f1463e70
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-09-29 06:43:44

Version Info:

CompanyName: Microsoft Corporation
FileDescription: MB Version update tool
FileVersion: 3.0.4506.5420 (Win7SP1.030729-5400)
InternalName: WsatConfig.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WsatConfig.exe
ProductName: Microsoft® .NET Framework
ProductVersion: 3.0.4506.5420
Comments: Flavor=Retail
PrivateBuild: DDBLD247
Translation: 0x0409 0x04b0

Malware.AI.507195241 also known as:

Elasticmalicious (high confidence)
SangforTrojan.Win32.Save.a
Cybereasonmalicious.5ad917
CyrenW32/MSIL_Agent.CHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:Malware-gen
ClamAVWin.Ransomware.WannaCry-9856297-0
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.af593451721014f2
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
MalwarebytesMalware.AI.507195241
APEXMalicious
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.D00F!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.507195241?

Malware.AI.507195241 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment